CVE-2007-5300

Publication date 9 October 2007

Last updated 24 July 2024


Ubuntu priority

Description

Off-by-one error in the do_login_loop function in libwzd-core/wzd_login.c in wzdftpd 0.8.0, 0.8.2, and possibly other versions allows remote attackers to cause a denial of service (daemon crash) via a long USER command that triggers a stack-based buffer overflow. NOTE: some of these details are obtained from third party information.

Read the notes from the security team

Status

Package Ubuntu Release Status
wzdftpd 7.10 gutsy
Fixed 0.8.2-2ubuntu2
7.04 feisty
Fixed 0.8.1-2ubuntu0.1
6.10 edgy
Fixed 0.7.2-4ubuntu0.1
6.06 LTS dapper
Fixed 0.6.1-1ubuntu1.1

Notes


jdstrand

appears a patch for Gutsy was commited on 2007/10/12

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
wzdftpd

Access our resources on patching vulnerabilities