security flaw
Published Aug 1, 2003
9.8
CRITICALCVSS 3.1
EPSS 78.11%
Description
Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code, as demonstrated in wu-ftpd 2.5.0 through 2.6.2 via commands that cause pathnames of length MAXPATHLEN+1 to trigger a buffer overflow, including (1) STOR, (2) RETR, (3) APPE, (4) DELE, (5) MKD, (6) RMD, (7) STOU, or (8) RNTO.
Affected products
No data.
Configuration 1
No data.
Red Hat Enterprise Linux AS (Advanced Server) version 2.1
n/a
Fixed · RHSA-2003:246
Red Hat Enterprise Linux ES version 2.1
n/a
Fixed · RHSA-2003:246
Red Hat Linux 7.1
n/a
Fixed · RHSA-2003:245
Red Hat Linux 7.2
n/a
Fixed · RHSA-2003:245
Red Hat Linux 7.3
n/a
Fixed · RHSA-2003:245
Red Hat Linux 8.0
n/a
Fixed · RHSA-2003:245
Red Hat Linux Advanced Workstation 2.1
n/a
Fixed · RHSA-2003:246
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux AS (Advanced Server) version 2.1 | n/a | Fixed | RHSA-2003:246 |
| Red Hat Enterprise Linux ES version 2.1 | n/a | Fixed | RHSA-2003:246 |
| Red Hat Linux 7.1 | n/a | Fixed | RHSA-2003:245 |
| Red Hat Linux 7.2 | n/a | Fixed | RHSA-2003:245 |
| Red Hat Linux 7.3 | n/a | Fixed | RHSA-2003:245 |
| Red Hat Linux 8.0 | n/a | Fixed | RHSA-2003:245 |
| Red Hat Linux Advanced Workstation 2.1 | n/a | Fixed | RHSA-2003:246 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:C/I:C/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (33 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 78.11% (0.78115) | 99.56th | v5 (v2026.06.15) |
| Jun 15, 2026 | 78.11% (0.78115) | 99.52th | v5 (v2026.06.15) |
| Mar 4, 2026 | 90.83% (0.90825) | 99.62th | v4 (v2025.03.14) |
| Mar 1, 2026 | 84.75% (0.84747) | 99.32th | v4 (v2025.03.14) |
| Feb 4, 2026 | 90.83% (0.90825) | 99.61th | v4 (v2025.03.14) |
| Feb 1, 2026 | 84.75% (0.84747) | 99.32th | v4 (v2025.03.14) |
| Jan 4, 2026 | 90.83% (0.90825) | 99.60th | v4 (v2025.03.14) |
| Jan 1, 2026 | 84.75% (0.84747) | 99.31th | v4 (v2025.03.14) |
| Dec 4, 2025 | 90.83% (0.90825) | 99.60th | v4 (v2025.03.14) |
| Dec 1, 2025 | 84.75% (0.84747) | 99.30th | v4 (v2025.03.14) |
| Nov 4, 2025 | 90.83% (0.90825) | 99.60th | v4 (v2025.03.14) |
| Nov 1, 2025 | 84.75% (0.84747) | 99.30th | v4 (v2025.03.14) |
| Oct 4, 2025 | 90.83% (0.90825) | 99.61th | v4 (v2025.03.14) |
| Oct 1, 2025 | 84.75% (0.84747) | 99.31th | v4 (v2025.03.14) |
| Sep 4, 2025 | 90.83% (0.90825) | 99.61th | v4 (v2025.03.14) |
| Sep 1, 2025 | 84.75% (0.84747) | 99.31th | v4 (v2025.03.14) |
| Aug 4, 2025 | 90.83% (0.90825) | 99.60th | v4 (v2025.03.14) |
| Aug 1, 2025 | 84.75% (0.84747) | 99.30th | v4 (v2025.03.14) |
| Jul 5, 2025 | 90.19% (0.90190) | 99.56th | v4 (v2025.03.14) |
| Jul 1, 2025 | 85.25% (0.85251) | 99.32th | v4 (v2025.03.14) |
| Jun 6, 2025 | 90.19% (0.90190) | 99.56th | v4 (v2025.03.14) |
| Jun 1, 2025 | 85.25% (0.85251) | 99.31th | v4 (v2025.03.14) |
| May 5, 2025 | 90.19% (0.90190) | 99.55th | v4 (v2025.03.14) |
| May 1, 2025 | 85.25% (0.85251) | 99.30th | v4 (v2025.03.14) |
| Mar 18, 2025 | 89.88% (0.89876) | 99.57th | v4 (v2025.03.14) |
| Mar 17, 2025 | 84.80% (0.84802) | 99.30th | v4 (v2025.03.14) |
| Dec 12, 2024 | 79.54% (0.79543) | 98.41th | v3 (v2023.03.01) |
| Feb 8, 2024 | 79.54% (0.79543) | 98.16th | v3 (v2023.03.01) |
| Jan 10, 2024 | 93.84% (0.93840) | 98.95th | v3 (v2023.03.01) |
| Aug 16, 2023 | 93.98% (0.93983) | 98.80th | v3 (v2023.03.01) |
| Mar 7, 2023 | 93.82% (0.93823) | 98.57th | v3 (v2023.03.01) |
| Mar 6, 2023 | 34.22% (0.34216) | 97.69th | v2 (v2022.01.01) |
| Feb 4, 2022 | 34.22% (0.34216) | 96.65th | v2 (v2022.01.01) |
References (31)
- ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-011.txt.asc vendor-advisoryx_refsource_NETBSDBroken Link
- http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0065.html mailing-listx_refsource_VULNWATCHBroken LinkExploitVendor Advisory
- http://download.immunix.org/ImmunixOS/7+/Updates/errata/IMNX-2003-7+-019-01 vendor-advisoryx_refsource_IMMUNIXBroken Link
- http://isec.pl/vulnerabilities/isec-0011-wu-ftpd.txt x_refsource_MISCBroken Link
- http://marc.info/?l=bugtraq&m=105967301604815&w=2 mailing-listx_refsource_BUGTRAQMailing List
- http://marc.info/?l=bugtraq&m=106001410028809&w=2 vendor-advisoryx_refsource_FREEBSDMailing List
- http://marc.info/?l=bugtraq&m=106001702232325&w=2 mailing-listx_refsource_BUGTRAQMailing List
- http://marc.info/?l=bugtraq&m=106002488209129&w=2 mailing-listx_refsource_BUGTRAQMailing List
- http://secunia.com/advisories/9423 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/9446 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/9447 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/9535 third-party-advisoryx_refsource_SECUNIABroken Link
- http://securitytracker.com/id?1007380 vdb-entryx_refsource_SECTRACKBroken LinkThird Party AdvisoryVDB Entry
- http://sunsolve.sun.com/search/document.do?assetkey=1-77-1001257.1-1 vendor-advisoryx_refsource_SUNALERTBroken Link
- http://www.debian.org/security/2003/dsa-357 vendor-advisoryx_refsource_DEBIANBroken Link
- http://www.kb.cert.org/vuls/id/743092 third-party-advisoryx_refsource_CERT-VNThird Party AdvisoryUS Government Resource
- http://www.mandriva.com/security/advisories?name=MDKSA-2003:080 vendor-advisoryx_refsource_MANDRAKEThird Party Advisory
- http://www.novell.com/linux/security/advisories/2003_032_wuftpd.html vendor-advisoryx_refsource_SUSEBroken Link
- http://www.osvdb.org/6602 vdb-entryx_refsource_OSVDBBroken Link
- http://www.redhat.com/support/errata/RHSA-2003-245.html vendor-advisoryx_refsource_REDHATBroken Link
- http://www.redhat.com/support/errata/RHSA-2003-246.html vendor-advisoryx_refsource_REDHATBroken Link
- http://www.securityfocus.com/archive/1/424852/100/0/threaded mailing-listx_refsource_BUGTRAQBroken LinkThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/archive/1/425061/100/0/threaded mailing-listx_refsource_BUGTRAQBroken LinkThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/8315 vdb-entryx_refsource_BIDBroken LinkExploitPatchThird Party AdvisoryVDB EntryVendor Advisory
- http://www.turbolinux.com/security/TLSA-2003-46.txt vendor-advisoryx_refsource_TURBOBroken Link
- https://access.redhat.com/security/cve/CVE-2003-0466 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1617041 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/12785 vdb-entryx_refsource_XFThird Party AdvisoryVDB Entry
- https://nvd.nist.gov/vuln/detail/CVE-2003-0466
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1970 vdb-entrysignaturex_refsource_OVALBroken Link
- https://www.cve.org/CVERecord?id=CVE-2003-0466
Change history (0)
No recorded changes yet.