CVE-2005-3524
linux-ftpd-ssl - buffer overflow
EPSS 21.5%
Description
Buffer overflow in the SSL-ready version of linux-ftpd (linux-ftpd-ssl) 0.17 allows remote attackers to execute arbitrary code by creating a long directory name, then executing the XPWD command.
How to fix CVE-2005-3524
To remediate CVE-2005-3524, upgrade the affected package to a fixed version below.
- Debian/linux-ftpd-ssl—upgrade to 0.17.18+0.3-5 or later
- Debian/linux-ftpd-ssl—upgrade to 0.17.18+0.3-3sarge1 or later
Is CVE-2005-3524 being exploited?
Moderate — EPSS is 21.5%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (2)
- from 0, < 0.17.18+0.3-5
- from 0, < 0.17.18+0.3-3sarge1