CVE-2005-0746
published 2005-05-02CVE-2005-0746: The Mini FTP server in Novell iChain 2.2 and 2.3 SP2 and earlier allows remote unauthenticated attackers to obtain the full path of the server via the PWD…
PriorityP423medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
1.81%
76.2th percentile
The Mini FTP server in Novell iChain 2.2 and 2.3 SP2 and earlier allows remote unauthenticated attackers to obtain the full path of the server via the PWD command.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| novell | ichain | — | — |
| novell | ichain | — | — |
| novell | ichain | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mmx6-pfm2-gv22: The Mini FTP server in Novell iChain 2
ghsa_unreviewed·2022-05-01
CVE-2005-0746 [MEDIUM] GHSA-mmx6-pfm2-gv22: The Mini FTP server in Novell iChain 2
The Mini FTP server in Novell iChain 2.2 and 2.3 SP2 and earlier allows remote unauthenticated attackers to obtain the full path of the server via the PWD command.
Red Hat
security flaw
vendor_redhat·2006-01-03·CVSS 7.5
CVE-2006-0746 [HIGH] security flaw
security flaw
Certain patches for kpdf do not include all relevant patches from xpdf that were associated with CVE-2005-3627, which allows context-dependent attackers to exploit vulnerabilities that were present in CVE-2005-3627.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2006-0746 security flaw
bugzilla·2018-08-16·CVSS 7.5
CVE-2006-0746 [HIGH] CVE-2006-0746 security flaw
CVE-2006-0746 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Certain patches for kpdf do not include all relevant patches from xpdf that were associated with CVE-2005-3627, which allows context-dependent attackers to exploit vulnerabilities that were present in CVE-2005-3627.
Bugzilla
CVE-2006-0746 kpdf buffer overflow
bugzilla·2006-03-07·CVSS 7.5
CVE-2006-0746 [HIGH] CVE-2006-0746 kpdf buffer overflow
CVE-2006-0746 kpdf buffer overflow
+++ This bug was initially created as a clone of Bug #184307 +++
The initial fix for CVE-2005-3627 was incomplete in kdegraphics.
The complete patch is attachment 125771
The reproducer is attachment 125772
Here is Chris Evans' original advisory, it has links to various other bad pdf files:
http://scary.beasts.org/security/CESA-2005-003.txt
Discussion:
there's kde-3.5.1 in FC4-update. It's not effected in this new kde version
http://www.kde.org/info/security/advisory-20060202-1.txt
Bugzilla
CVE-2006-0746 kpdf buffer overflow
bugzilla·2006-03-07·CVSS 7.5
CVE-2006-0746 [HIGH] CVE-2006-0746 kpdf buffer overflow
CVE-2006-0746 kpdf buffer overflow
The initial fix for CVE-2005-3627 was incomplete in kdegraphics.
The complete patch is attachment 125771
The reproducer is attachment 125772
Here is Chris Evans' original advisory, it has links to various other bad pdf files:
http://scary.beasts.org/security/CESA-2005-003.txt
Discussion:
it's now fixed in kdegraphics-3.3.1-3.9
---
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.
http://rhn.redhat.com/errata/RHSA-2006-0262.html
http://marc.info/?l=bugtraq&m=111091102023359&w=2http://secunia.com/advisories/14537http://securitytracker.com/id?1013407http://support.novell.com/cgi-bin/search/searchtid.cgi?/10096886.htmhttp://www.infobyte.com.ar/adv/ISR-03.htmlhttp://www.securityfocus.com/bid/12766https://exchange.xforce.ibmcloud.com/vulnerabilities/19643http://marc.info/?l=bugtraq&m=111091102023359&w=2http://secunia.com/advisories/14537http://securitytracker.com/id?1013407http://support.novell.com/cgi-bin/search/searchtid.cgi?/10096886.htmhttp://www.infobyte.com.ar/adv/ISR-03.htmlhttp://www.securityfocus.com/bid/12766https://exchange.xforce.ibmcloud.com/vulnerabilities/19643
2005-05-02
Published