CVE-2007-6263
EPSS 2.5%
描述
The dataconn function in ftpd.c in netkit ftpd (netkit-ftpd) 0.17, when certain modifications to support SSL have been introduced, calls fclose on an uninitialized file stream, which allows remote attackers to cause a denial of service (daemon crash) and possibly have unspecified other impact via some types of FTP over SSL protocol behavior, as demonstrated by breaking a passive FTP DATA connection in a way that triggers an error in the server's SSL_accept function. NOTE: the netkit ftp issue is covered by CVE-2007-5769.
如何修補 CVE-2007-6263
要修補 CVE-2007-6263,請將受影響套件升級到下列已修補版本。
- Debian/linux-ftpd-ssl—升級至 0.17.18+0.3-9.1 或更新版本
CVE-2007-6263 正在被利用嗎?
低 — EPSS 為 2.5%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- from 0, < 0.17.18+0.3-9.1