CVE-2003-0963
EPSS 15.4%lftp - buffer overflow
Published: 1/5/2004Modified: 4/28/2026
Also known as:DEBIAN-CVE-2003-0963
Description
Buffer overflows in (1) try_netscape_proxy and (2) try_squid_eplf for lftp 2.6.9 and earlier allow remote HTTP servers to execute arbitrary code via long directory names that are processed by the ls or rels commands.
Affected packages (2)
- Debian/lftpfrom 0, < 2.6.10-1
- Debian/lftpfrom 0, < 2.4.9-1woody2