CVE-2010-4652
Published Feb 2, 2011
Last updated 14 years ago
Overview
- Description
- Heap-based buffer overflow in the sql_prepare_where function (contrib/mod_sql.c) in ProFTPD before 1.3.3d, when mod_sql is enabled, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted username containing substitution tags, which are not properly handled during construction of an SQL query.
- Source
- secalert@redhat.com
- NVD status
- Modified
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 6.8
- Impact score
- 6.4
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- CWE-119
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:proftpd:proftpd:*:c:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9BC31541-B666-4379-B6F8-C3F29CC0F2BA", "versionEndIncluding": "1.3.3" }, { "criteria": "cpe:2.3:a:proftpd:proftpd:1.2.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B472294D-A2FE-4654-A074-8AA07E372FC3" }, { "criteria": "cpe:2.3:a:proftpd:proftpd:1.2.0:pre10:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8F6FAFE7-CA48-4CB3-9D2C-93885CBD0E31" }, { "criteria": "cpe:2.3:a:proftpd:proftpd:1.2.0:pre9:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "66B905D9-D4B2-4133-9918-EB54C48319C9" }, { "criteria": "cpe:2.3:a:proftpd:proftpd:1.2.0:rc1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BC4021B3-9847-43A1-96A1-0853607B5A1A" }, { "criteria": "cpe:2.3:a:proftpd:proftpd:1.2.0:rc2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1C874862-2902-4927-8BE4-D90CCBBDE1CD" }, { "criteria": "cpe:2.3:a:proftpd:proftpd:1.2.0:rc3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "12BBE1F6-0095-4D59-AB85-AD156B4E6330" }, { "criteria": "cpe:2.3:a:proftpd:proftpd:1.2.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8FAB5B28-F80C-4B1E-84A3-897C1C31E10F" }, { "criteria": "cpe:2.3:a:proftpd:proftpd:1.2.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AB42F122-F661-4039-8E55-394BF1DDBAF0" }, { "criteria": "cpe:2.3:a:proftpd:proftpd:1.2.2:rc1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D8258B2B-CE41-4631-9BE2-851BF1EEFBB6" }, { "criteria": "cpe:2.3:a:proftpd:proftpd:1.2.2:rc2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "98BAB5CF-A079-44B7-8F16-5B9042C7AD85" }, { "criteria": "cpe:2.3:a:proftpd:proftpd:1.2.2:rc3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "793E0643-019A-4B59-899C-05D62217CA32" }, { "criteria": "cpe:2.3:a:proftpd:proftpd:1.2.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E07A224A-CB33-4E60-B61D-C39921357752" }, { "criteria": "cpe:2.3:a:proftpd:proftpd:1.2.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "09E592E6-7CCC-49D0-84A6-D2FF39B87B26" }, { "criteria": "cpe:2.3:a:proftpd:proftpd:1.2.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9E5306B2-CA16-40F2-B2D7-CAC8F6B300FE" }, { "criteria": "cpe:2.3:a:proftpd:proftpd:1.2.5:rc1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "68017302-B9B2-4CE2-8337-DDC955328B02" }, { "criteria": "cpe:2.3:a:proftpd:proftpd:1.2.5:rc2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5759F3EA-795E-44AC-876F-64EACBAE1F13" }, { "criteria": "cpe:2.3:a:proftpd:proftpd:1.2.5:rc3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "943E8AF1-1EE9-4373-84CB-17092692EFD9" }, { "criteria": "cpe:2.3:a:proftpd:proftpd:1.2.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6DE8A2A3-E0C9-4287-B2A3-9AF7AC6BA4B1" }, { "criteria": "cpe:2.3:a:proftpd:proftpd:1.2.6:rc1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C5B04A95-766E-4191-8B5C-DDABF947992A" }, { "criteria": "cpe:2.3:a:proftpd:proftpd:1.2.6:rc2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "92565089-853E-400B-89D4-FE95C701CF66" }, { "criteria": "cpe:2.3:a:proftpd:proftpd:1.2.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "092FB5B4-C960-4354-AB39-CF1282F8F6CD" }, { "criteria": "cpe:2.3:a:proftpd:proftpd:1.2.7:rc1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AB0767FF-3FEA-4F1C-B307-B55797257092" }, { "criteria": "cpe:2.3:a:proftpd:proftpd:1.2.7:rc2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F7C739C5-5647-4F77-82F6-59A868E29A49" }, { "criteria": "cpe:2.3:a:proftpd:proftpd:1.2.7:rc3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "933CE353-B6F5-45C0-B011-32F0864AB95E" }, { "criteria": "cpe:2.3:a:proftpd:proftpd:1.2.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "991E4BED-A675-4D44-9A72-EE7F49005B20" }, { "criteria": "cpe:2.3:a:proftpd:proftpd:1.2.8:rc1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A8B64256-9994-4D7B-928C-3DAEC0B2CE63" }, { "criteria": "cpe:2.3:a:proftpd:proftpd:1.2.8:rc2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EC180DEA-985D-4802-BCA3-99025C695A14" }, { "criteria": "cpe:2.3:a:proftpd:proftpd:1.2.9:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8EC036C6-445D-4A6E-8B22-799CE611C05C" }, { "criteria": "cpe:2.3:a:proftpd:proftpd:1.2.9:rc1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "44670EA1-33E7-486B-80C0-743C09632F65" }, { "criteria": "cpe:2.3:a:proftpd:proftpd:1.2.9:rc2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "777FBAE6-3BA4-436A-85FC-B59DCFB89160" }, { "criteria": "cpe:2.3:a:proftpd:proftpd:1.2.9:rc3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9974BFCD-08A3-4971-B075-3F0D02127C84" }, { "criteria": "cpe:2.3:a:proftpd:proftpd:1.2.10:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "67473C1E-95B5-43A2-A0DB-F65FD239DB38" }, { "criteria": "cpe:2.3:a:proftpd:proftpd:1.2.10:rc1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "17FA3F4E-49CB-4C61-BED8-466F4DB61ED1" }, { "criteria": "cpe:2.3:a:proftpd:proftpd:1.2.10:rc2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1239A9F8-3EE5-4CF1-8F02-D2F5F26F708E" }, { "criteria": "cpe:2.3:a:proftpd:proftpd:1.2.10:rc3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5DE6D2B3-BD20-4361-AFDA-9B8368944588" }, { "criteria": "cpe:2.3:a:proftpd:proftpd:1.3.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BA3DED96-536B-4974-9F90-BBEA80408845" }, { "criteria": "cpe:2.3:a:proftpd:proftpd:1.3.0:a:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EA19FBBE-EEC7-4575-9D5F-7A8458A357AB" }, { "criteria": "cpe:2.3:a:proftpd:proftpd:1.3.0:rc1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3744E1A8-516E-4E47-851E-BC3877DEE2F6" }, { "criteria": "cpe:2.3:a:proftpd:proftpd:1.3.0:rc2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0C34711E-E228-47E7-B2CB-CB10AD121953" }, { "criteria": "cpe:2.3:a:proftpd:proftpd:1.3.0:rc3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E3A1304E-22C2-43F1-90DF-874466CF3A35" }, { "criteria": "cpe:2.3:a:proftpd:proftpd:1.3.0:rc4:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "75841353-74FD-4DDB-B73F-16BB01A48D73" }, { "criteria": "cpe:2.3:a:proftpd:proftpd:1.3.0:rc5:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B1362BD4-8CB4-4C53-BE42-88ADC3E505A6" }, { "criteria": "cpe:2.3:a:proftpd:proftpd:1.3.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0629F25F-B9C6-4FC7-B67E-E6B38E59E60B" }, { "criteria": "cpe:2.3:a:proftpd:proftpd:1.3.1:rc1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "24F20C0A-354D-496B-B287-50CB5C4F3291" }, { "criteria": "cpe:2.3:a:proftpd:proftpd:1.3.1:rc2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C39649BE-9048-44BA-8D47-6D37DCDEFA5E" }, { "criteria": "cpe:2.3:a:proftpd:proftpd:1.3.1:rc3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8697292B-16DF-4300-8F90-8E72D4968E9F" }, { "criteria": "cpe:2.3:a:proftpd:proftpd:1.3.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "185E727C-E4DB-4713-866D-957D20838D97" }, { "criteria": "cpe:2.3:a:proftpd:proftpd:1.3.2:a:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "68E1D21D-CAEF-4EAC-8ABE-1ED87EFEFD0A" }, { "criteria": "cpe:2.3:a:proftpd:proftpd:1.3.2:b:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A34C4EE8-34D6-44E5-8B11-F8A07CFC021D" }, { "criteria": "cpe:2.3:a:proftpd:proftpd:1.3.2:c:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FBAD4AD3-3EC7-4A82-8AEE-D5795343B8B9" }, { "criteria": "cpe:2.3:a:proftpd:proftpd:1.3.2:d:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C231AC26-6DDD-4394-A1CC-528D997AB4E6" }, { "criteria": "cpe:2.3:a:proftpd:proftpd:1.3.2:e:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A1D1F6FD-50B2-4128-B4D1-61E47DA2AF20" }, { "criteria": "cpe:2.3:a:proftpd:proftpd:1.3.2:rc1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8B43EDB7-7B67-43E0-AAE9-F8120C6E607C" }, { "criteria": "cpe:2.3:a:proftpd:proftpd:1.3.2:rc2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F615B39A-5E30-454B-B851-14C5735578E3" }, { "criteria": "cpe:2.3:a:proftpd:proftpd:1.3.2:rc3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B9C16C32-7834-4363-A0BE-A776A6DB307A" }, { "criteria": "cpe:2.3:a:proftpd:proftpd:1.3.2:rc4:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5884F593-C977-4AFC-9428-6A915D962C97" }, { "criteria": "cpe:2.3:a:proftpd:proftpd:1.3.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6402CD88-0255-4574-8772-8723883FBFAF" }, { "criteria": "cpe:2.3:a:proftpd:proftpd:1.3.3:a:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6FDFFB0F-0F4D-4388-B5D4-4E217234AADD" }, { "criteria": "cpe:2.3:a:proftpd:proftpd:1.3.3:b:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A1D5B657-62CB-4C31-9798-C529C22EA7D6" }, { "criteria": "cpe:2.3:a:proftpd:proftpd:1.3.3:rc1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "29FBDF30-0E17-46DA-8548-DEE5E3CD9EAB" }, { "criteria": "cpe:2.3:a:proftpd:proftpd:1.3.3:rc2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D78D0553-7C43-4032-A573-16CC45A24386" }, { "criteria": "cpe:2.3:a:proftpd:proftpd:1.3.3:rc3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FAEEEE3C-7EAA-419F-9BF7-333B63DCDA3F" }, { "criteria": "cpe:2.3:a:proftpd:proftpd:1.3.3:rc4:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F68C4EEA-FA42-4B99-8EA6-3DB57527947B" } ], "operator": "OR" } ] } ]