CVE-2010-1938
28.05.2010, 18:30
Off-by-one error in the __opiereadrec function in readrec.c in libopie in OPIE 2.4.1-test1 and earlier, as used on FreeBSD 6.4 through 8.1-PRERELEASE and other platforms, allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a long username, as demonstrated by a long USER command to the FreeBSD 8.0 ftpd.Enginsight
Vendor | Product | Version |
---|---|---|
freebsd | freebsd | 6.4 |
freebsd | freebsd | 6.4:release |
freebsd | freebsd | 6.4:release_p2 |
freebsd | freebsd | 6.4:release_p3 |
freebsd | freebsd | 6.4:release_p4 |
freebsd | freebsd | 6.4:release_p5 |
freebsd | freebsd | 6.4:stable |
freebsd | freebsd | 7.0 |
freebsd | freebsd | 7.0:beta_4 |
freebsd | freebsd | 7.0:current |
freebsd | freebsd | 7.0:pre-release |
freebsd | freebsd | 7.0:release |
freebsd | freebsd | 7.0:release-p12 |
freebsd | freebsd | 7.0:release-p8 |
freebsd | freebsd | 7.0:release-p9 |
freebsd | freebsd | 7.0:releng |
freebsd | freebsd | 7.0:stable |
freebsd | freebsd | 7.0-release |
freebsd | freebsd | 7.0_beta4:_beta4 |
freebsd | freebsd | 7.0_releng:_releng |
freebsd | freebsd | 7.1 |
freebsd | freebsd | 7.1:pre-release |
freebsd | freebsd | 7.1:rc1 |
freebsd | freebsd | 7.1:release-p1 |
freebsd | freebsd | 7.1:release-p2 |
freebsd | freebsd | 7.1:release-p4 |
freebsd | freebsd | 7.1:release-p5 |
freebsd | freebsd | 7.1:release-p6 |
freebsd | freebsd | 7.1:stable |
freebsd | freebsd | 7.2 |
freebsd | freebsd | 7.2:pre-release |
freebsd | freebsd | 7.2:stable |
freebsd | freebsd | 8.0 |
freebsd | freebsd | 8.1-prerelease |
nrl | opie | 𝑥 ≤ 2.4.1 |
nrl | opie | 2.2 |
nrl | opie | 2.3 |
nrl | opie | 2.4 |
nrl | opie | 2.10 |
nrl | opie | 2.11 |
nrl | opie | 2.21 |
nrl | opie | 2.22 |
nrl | opie | 2.32 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration
References