CVE-2009-4593: Medium severity bftpd vulnerability
Published Jan 7, 2010
·Updated
The bftpdutmplog function in bftpdutmp.c in Bftpd before 2.4 does not place a '\0' character at the end of the string value of the ut.buhost structure member, which might allow remote attackers to cause a denial of service (daemon crash) via unspecified vectors. NOTE: some of these details are obtained from third party information.
Affected Software
12 affected components
Jesse Smith Bftpd<=2.3
Jesse Smith Bftpd=1.6
Jesse Smith Bftpd=1.7
Jesse Smith Bftpd=1.7.2
Jesse Smith Bftpd=1.8
Jesse Smith Bftpd=2.0.2
Jesse Smith Bftpd=2.0.3
Jesse Smith Bftpd=2.1
Jesse Smith Bftpd=2.1.1
Jesse Smith Bftpd=2.1.2
Jesse Smith Bftpd=2.2
Jesse Smith Bftpd=2.2.1
Remediation
Patch Available
Patch Available
Patch Available
Event History
Jan 7, 2010
CVE Published
via MITRE·06:13 PM
Data Sourced
via MITRE·06:13 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-4593?
CVE-2009-4593 has been classified as a denial of service vulnerability that can lead to daemon crashes.
2
How do I fix CVE-2009-4593?
To fix CVE-2009-4593, update Bftpd to version 2.4 or later.
3
Which versions of Bftpd are affected by CVE-2009-4593?
Versions of Bftpd prior to 2.4, including 1.6, 1.7, 1.8, and 2.2.1, are affected by CVE-2009-4593.
4
What kind of attack is facilitated by CVE-2009-4593?
CVE-2009-4593 allows remote attackers to potentially cause a denial of service through unspecified vectors.
5
When was CVE-2009-4593 first reported?
CVE-2009-4593 was reported in December 2009.