CVE-2001-0248Incorrect Calculation of Buffer Size in HP Hp-ux

Severity
9.8CRITICALNVD
EPSS
5.3%
top 9.94%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 18
Latest updateApr 30

Description

Buffer overflow in FTP server in HPUX 11 allows remote attackers to execute arbitrary commands by creating a long pathname and calling the STAT command, which uses glob to generate long strings.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

NVDhp/hp-ux11.00
NVDsgi/irix6.5, 6.5.1, 6.5.2+2

Patches

🔴Vulnerability Details

2
GHSA
GHSA-6m44-c224-92xx: Buffer overflow in FTP server in HPUX 11 allows remote attackers to execute arbitrary commands by creating a long pathname and calling the STAT comman2022-04-30
CVEList
CVE-2001-0248: Buffer overflow in FTP server in HPUX 11 allows remote attackers to execute arbitrary commands by creating a long pathname and calling the STAT comman2001-05-24
CVE-2001-0248 — Incorrect Calculation of Buffer Size | cvebase