CVE-2009-4593

The bftpdutmp_log function in bftpdutmp.c in Bftpd before 2.4 does not place a '\0' character at the end of the string value of the ut.bu_host structure member, which might allow remote attackers to cause a denial of service (daemon crash) via unspecified vectors. NOTE: some of these details are obtained from third party information.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:N/I:N/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 71%
VendorProductVersion
jesse_smithbftpd
𝑥
≤ 2.3
jesse_smithbftpd
1.6
jesse_smithbftpd
1.7
jesse_smithbftpd
1.7.2
jesse_smithbftpd
1.8
jesse_smithbftpd
2.0.2
jesse_smithbftpd
2.0.3
jesse_smithbftpd
2.1
jesse_smithbftpd
2.1.1
jesse_smithbftpd
2.1.2
jesse_smithbftpd
2.2
jesse_smithbftpd
2.2.1
𝑥
= Vulnerable software versions