CVE-2010-1938: Critical severity FreeBSD FreeBSD vulnerability
Off-by-one error in the opiereadrec function in readrec.c in libopie in OPIE 2.4.1-test1 and earlier, as used on FreeBSD 6.4 through 8.1-PRERELEASE and other platforms, allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a long username, as demonstrated by a long USER command to the FreeBSD 8.0 ftpd.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-1938?
CVE-2010-1938 is considered to have a high severity due to its potential to cause a denial of service and possible remote code execution.
How do I fix CVE-2010-1938?
To fix CVE-2010-1938, upgrade to a patched version of libopie that addresses the off-by-one error.
Which systems are affected by CVE-2010-1938?
CVE-2010-1938 affects FreeBSD versions 6.4 through 8.1-PRERELEASE and earlier versions of libopie, specifically prior to 2.4.1-test1.
What type of vulnerability is CVE-2010-1938?
CVE-2010-1938 is classified as an off-by-one error vulnerability.
Can CVE-2010-1938 lead to remote code execution?
Yes, CVE-2010-1938 can potentially allow remote attackers to execute arbitrary code.