CVE-2006-6652: Buffer Overflow
Buffer overflow in the glob implementation (glob.c) in libc in NetBSD-current before 20050914, NetBSD 2. and 3. before 20061203, and Apple Mac OS X before 2007-004, as used by the FTP daemon and tnftpd, allows remote authenticated users to execute arbitrary code via a long pathname that results from path expansion.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-6652?
CVE-2006-6652 has a moderate severity rating due to its potential for remote code execution through a buffer overflow.
How do I fix CVE-2006-6652?
To mitigate CVE-2006-6652, users should upgrade to the latest version of NetBSD or Mac OS X that includes the official security patches.
Who is affected by CVE-2006-6652?
CVE-2006-6652 affects users of NetBSD versions prior to 20061203 and Apple Mac OS X versions before 2007-004.
What types of systems are impacted by CVE-2006-6652?
CVE-2006-6652 impacts systems running vulnerable versions of the NetBSD operating system and certain versions of Apple Mac OS X.
What is the nature of the vulnerability identified in CVE-2006-6652?
CVE-2006-6652 is a buffer overflow vulnerability caused by improper handling of long pathnames in the glob implementation.