CVE-2011-2523: OS Command Injection
Published Nov 27, 2019
·Updated
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
Affected Software
5 affected componentsFixes available
Vsftpd Project Vsftpd=2.3.4
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Debian Debian Linux=10.0
debian/vsftpd
3.0.3-123.0.3-133.0.5-0.23.0.5-0.4
Event History
Nov 27, 2019
CVE Published
via MITRE·08:36 PM
Data Sourced
via MITRE·08:36 PM
DescriptionWeakness
Feb 17, 2026
Data Sourced
via Debian·11:43 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is CVE-2011-2523?
CVE-2011-2523 is a vulnerability in vsftpd 2.3.4 that contains a backdoor which opens a shell on port 6200/tcp.
2
What is the severity of CVE-2011-2523?
The severity of CVE-2011-2523 is critical, with a severity value of 9.8.
3
Which software versions are affected by CVE-2011-2523?
vsftpd 2.3.4 and Debian Linux versions 8.0, 9.0, and 10.0 are affected by CVE-2011-2523.
4
How do I fix CVE-2011-2523 in vsftpd?
To fix CVE-2011-2523 in vsftpd, update to version 3.0.3-12 or 3.0.3-13.
5
Where can I get more information about CVE-2011-2523?
You can get more information about CVE-2011-2523 from the following sources: [link1](https://security-tracker.debian.org/tracker/CVE-2011-2523), [link2](https://www.openwall.com/lists/oss-security/2011/07/11/5), [link3](https://vigilance.fr/vulnerability/vsftpd-backdoor-in-version-2-3-4-10805).