CVE-2006-5000: Buffer Overflow
Multiple buffer overflows in WSFTP Server 5.05 before Hotfix 1, and possibly other versions down to 5.0, have unknown impact and remote authenticated attack vectors via the (1) XCRC, (2) XMD5, and (3) XSHA1 commands. NOTE: in the early publication of this identifier on 20060926, the description was used for the wrong issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2006-5000?
CVE-2006-5000 has an unknown impact but involves multiple buffer overflows, which typically indicate a serious security vulnerability.
How do I fix CVE-2006-5000?
To fix CVE-2006-5000, apply Hotfix 1 for WS_FTP Server 5.05 or upgrade to a later version that addresses the vulnerability.
Which versions of WS_FTP Server are affected by CVE-2006-5000?
CVE-2006-5000 affects WS_FTP Server versions 5.0.2, 5.03, and 5.05, prior to Hotfix 1.
Who is the vendor for CVE-2006-5000?
The vendor for CVE-2006-5000 is Ipswitch, Inc., which developed the WS_FTP Server.
What are the attack vectors for CVE-2006-5000?
CVE-2006-5000 can be exploited via remote authenticated attack vectors using the XCRC, XMD5, and XSHA1 commands.