Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2003-0963Improper Restriction of Operations within the Bounds of a Memory Buffer in Lftp

7 documents7 sources
Severity
7.5HIGHNVD
EPSS
15.4%
top 5.34%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedJan 5
Latest updateMay 3

Description

Buffer overflows in (1) try_netscape_proxy and (2) try_squid_eplf for lftp 2.6.9 and earlier allow remote HTTP servers to execute arbitrary code via long directory names that are processed by the ls or rels commands.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages3 packages

debiandebian/lftp< lftp 2.6.10-1 (bookworm)
Debianalexander_v_lukyanov/lftp< 2.6.10-1+3
NVDalexander_v_lukyanov/lftp11 versions+10

🔴Vulnerability Details

2
GHSA
GHSA-pv7m-39mr-v2jm: Buffer overflows in (1) try_netscape_proxy and (2) try_squid_eplf for lftp 22022-05-03
OSV
CVE-2003-0963: Buffer overflows in (1) try_netscape_proxy and (2) try_squid_eplf for lftp 22004-01-05

💥Exploits & PoCs

1
Exploit-DB
lftp 2.6.9 - Remote Stack Overflow2004-01-14

📋Vendor Advisories

2
Red Hat
security flaw2003-12-13
Debian
CVE-2003-0963: lftp - Buffer overflows in (1) try_netscape_proxy and (2) try_squid_eplf for lftp 2.6.9...2003

💬Community

1
Bugzilla
CVE-2003-0963 security flaw2018-08-16