CVE-2007-6263
EPSS 2.5%
Description
The dataconn function in ftpd.c in netkit ftpd (netkit-ftpd) 0.17, when certain modifications to support SSL have been introduced, calls fclose on an uninitialized file stream, which allows remote attackers to cause a denial of service (daemon crash) and possibly have unspecified other impact via some types of FTP over SSL protocol behavior, as demonstrated by breaking a passive FTP DATA connection in a way that triggers an error in the server's SSL_accept function. NOTE: the netkit ftp issue is covered by CVE-2007-5769.
How to fix CVE-2007-6263
To remediate CVE-2007-6263, upgrade the affected package to a fixed version below.
- Debian/linux-ftpd-ssl—upgrade to 0.17.18+0.3-9.1 or later
Is CVE-2007-6263 being exploited?
Low — EPSS is 2.5%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 0.17.18+0.3-9.1