Loading...
Loading...
Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code, as demonstrated in wu-ftpd 2.5.0 through 2.6.2 via commands that cause pathnames of length MAXPATHLEN+1 to trigger a buffer overflow, including (1) STOR, (2) RETR, (3) APPE, (4) DELE, (5) MKD, (6) RMD, (7) STOU, or (8) RNTO.
August 27, 2003
April 16, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2003-0466
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.