FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

fsp buffer overflow and directory traversal vulnerabilities

Affected packages
fspd < 2.8.1.19

Details

VuXML ID 20be2982-4aae-11d8-96f2-0020ed76ef5a
Discovery 2004-01-06
Entry 2004-01-19
Modified 2004-05-17

The Debian security team reported a pair of vulnerabilities in fsp:

A vulnerability was discovered in fsp, client utilities for File Service Protocol (FSP), whereby a remote user could both escape from the FSP root directory (CAN-2003-1022), and also overflow a fixed-length buffer to execute arbitrary code (CAN-2004-0011).

References

CVE Name CVE-2003-1022
CVE Name CVE-2004-0011
URL http://www.debian.org/security/2004/dsa-416