First published: Thu Aug 19 2004(Updated: )
Multiple signal handler race conditions in lukemftpd (aka tnftpd before 20040810) allow remote authenticated attackers to cause a denial of service or execute arbitrary code.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Luke Mewburn lukemftp | =1.5 | |
Luke Mewburn TNFtpd | =2003-12-17 | |
Luke Mewburn lukemftp | =1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-0794 has a severity rating of high due to its potential to allow remote code execution and denial of service.
To fix CVE-2004-0794, you need to update to the latest version of lukemftpd or tnftpd where the vulnerability has been patched.
CVE-2004-0794 affects lukemftpd version 1.5, tnftpd version 2003-12-17, and lukemftpd version 1.1.
Yes, CVE-2004-0794 can be exploited by remote authenticated attackers to execute arbitrary code.
CVE-2004-0794 includes multiple race conditions in signal handlers leading to denial of service or remote code execution.