CVE-2012-6067

freeFTPd.exe in freeFTPd through 1.0.11 allows remote attackers to bypass authentication via a crafted SFTP session, as demonstrated by an OpenSSH client with modified versions of ssh.c and sshconnect2.c.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:freeftpd:freeftpd:*:*:*:*:*:*:*:*
cpe:2.3:a:freeftpd:freeftpd:1.0:*:*:*:*:*:*:*
cpe:2.3:a:freeftpd:freeftpd:1.0.1:*:*:*:*:*:*:*
cpe:2.3:a:freeftpd:freeftpd:1.0.2:*:*:*:*:*:*:*
cpe:2.3:a:freeftpd:freeftpd:1.0.3:*:*:*:*:*:*:*
cpe:2.3:a:freeftpd:freeftpd:1.0.4:*:*:*:*:*:*:*
cpe:2.3:a:freeftpd:freeftpd:1.0.5:*:*:*:*:*:*:*
cpe:2.3:a:freeftpd:freeftpd:1.0.6:*:*:*:*:*:*:*
cpe:2.3:a:freeftpd:freeftpd:1.0.7:*:*:*:*:*:*:*
cpe:2.3:a:freeftpd:freeftpd:1.0.8:*:*:*:*:*:*:*
cpe:2.3:a:freeftpd:freeftpd:1.0.10:*:*:*:*:*:*:*

History

21 Nov 2024, 01:45

Type Values Removed Values Added
References () http://archives.neohapsis.com/archives/fulldisclosure/2012-12/0011.html - () http://archives.neohapsis.com/archives/fulldisclosure/2012-12/0011.html -

Information

Published : 2012-12-04 23:55

Updated : 2024-11-21 01:45


NVD link : CVE-2012-6067

Mitre link : CVE-2012-6067

CVE.ORG link : CVE-2012-6067


JSON object : View

Products Affected

freeftpd

  • freeftpd
CWE
CWE-287

Improper Authentication