CVE-2005-3683: Buffer Overflow
Published Nov 19, 2005
·Updated
Stack-based buffer overflow in freeFTPd before 1.0.9 with Logging enabled, allows remote attackers to cause a denial of service (application crash), and possibly execute arbitrary code, via a long USER command.
Affected Software
9 affected components
freeFTPd freeFTPd=1.0.2
freeFTPd freeFTPd=1.0.3
freeFTPd freeFTPd=1.0
freeFTPd freeFTPd=1.0.5
freeFTPd freeFTPd=1.0.1
freeFTPd freeFTPd=1.0.4
freeFTPd freeFTPd=1.0.8
freeFTPd freeFTPd=1.0.6
freeFTPd freeFTPd=1.0.7
Remediation
Patch Available
Patch Available
Event History
Nov 19, 2005
CVE Published
01:03 AM
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-3683?
CVE-2005-3683 is classified as a high severity vulnerability due to its potential to allow remote attackers to execute arbitrary code.
2
How do I fix CVE-2005-3683?
To fix CVE-2005-3683, update freeFTPd to version 1.0.9 or later.
3
What software is affected by CVE-2005-3683?
CVE-2005-3683 affects freeFTPd versions 1.0.0 through 1.0.8.
4
What kind of attack does CVE-2005-3683 allow?
CVE-2005-3683 allows a stack-based buffer overflow attack through a long USER command.
5
What are the consequences of CVE-2005-3683?
The consequences of CVE-2005-3683 include denial of service and potential unauthorized arbitrary code execution.