First published: Thu Feb 10 2005(Updated: )
Buffer overflow in the FTP service in 3Com 3CDaemon 2.0 revision 10 allows remote attackers to cause a denial of service (application crash) and execute arbitrary code via (1) a long username in the USER command or (2) an FTP command that contains a long argument, such as cd, send, or ls.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
3Com 3CDaemon | =2.0-revision_10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-0277 is considered to have a high severity due to the potential for remote code execution and denial of service.
To fix CVE-2005-0277, you should apply any available patches for 3Com 3CDaemon or upgrade to a more secure version.
CVE-2005-0277 exposes the FTP service to a buffer overflow, allowing attackers to crash the application or execute arbitrary code.
CVE-2005-0277 can primarily be exploited by remote attackers through specially crafted FTP commands.
The attack vectors for CVE-2005-0277 include using long usernames or long arguments in FTP commands like USER, cd, send, or ls.