CVE-2006-6170

Aliases:DEBIAN-CVE-2006-6170
Advisory lineage Upstream: 0 Downstream: 2
Modified
Published: 30 Nov 2006, 15:00
Last modified:07 Aug 2024, 20:19

Vulnerability Summary

Overall Risk (default)
medium
43/100
CVSS Score
7.5 HIGH
v2.0 (nvd)
EPSS Score
17.1% MEDIUM
17% probability +2.72%
KEV
Not listed
Ransomware
No reports
Public exploits
2 found
Dark Web
Not detected

Timeline

30 Nov 2006, 15:00
Published
Vulnerability first disclosed
07 Aug 2024, 20:19
Last Modified
Vulnerability information updated

Description

Buffer overflow in the tls_x509_name_oneline function in the mod_tls module, as used in ProFTPD 1.3.0a and earlier, and possibly other products, allows remote attackers to execute arbitrary code via a large data length argument, a different vulnerability than CVE-2006-5815.

CVSS Metrics

  • v2.0HIGHScore: 7.5AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS Trends

Current EPSS score: 17.10% Percentile: 97%

Affected Systems

  • debianproftpd-dfsg

    < 1.3.0-16 | < 1.3.0-16 | < 1.3.0-16 | < 1.3.0-16

  • proftpd_projectproftpd

    ≤ 1.3.0a

References (20)