Off-by-one error in the __opiereadrec function in readrec.c in libopie in OPIE 2.4.1-test1 and earlier, as used on FreeBSD 6.4 through 8.1-PRERELEASE and other platforms, allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a long username, as demonstrated by a long USER command to the FreeBSD 8.0 ftpd.
2010-05-28T18:30:01.470
2025-04-11T00:51:21.963
Deferred
CVSSv2: 9.3 (HIGH)
AV:N/AC:M/Au:N/C:C/I:C/A:C
8.6
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | freebsd | freebsd | 6 | Yes |
Operating System | freebsd | freebsd | 6.4 | Yes |
Operating System | freebsd | freebsd | 6.4 | Yes |
Operating System | freebsd | freebsd | 6.4 | Yes |
Operating System | freebsd | freebsd | 6.4 | Yes |
Operating System | freebsd | freebsd | 6.4 | Yes |
Operating System | freebsd | freebsd | 6.4 | Yes |
Operating System | freebsd | freebsd | 6.4 | Yes |
Operating System | freebsd | freebsd | 7.0 | Yes |
Operating System | freebsd | freebsd | 7.0 | Yes |
Operating System | freebsd | freebsd | 7.0 | Yes |
Operating System | freebsd | freebsd | 7.0 | Yes |
Operating System | freebsd | freebsd | 7.0 | Yes |
Operating System | freebsd | freebsd | 7.0 | Yes |
Operating System | freebsd | freebsd | 7.0 | Yes |
Operating System | freebsd | freebsd | 7.0 | Yes |
Operating System | freebsd | freebsd | 7.0 | Yes |
Operating System | freebsd | freebsd | 7.0 | Yes |
Operating System | freebsd | freebsd | 7.0-release | Yes |
Operating System | freebsd | freebsd | 7.0_beta4 | Yes |
Operating System | freebsd | freebsd | 7.0_releng | Yes |
Operating System | freebsd | freebsd | 7.1 | Yes |
Operating System | freebsd | freebsd | 7.1 | Yes |
Operating System | freebsd | freebsd | 7.1 | Yes |
Operating System | freebsd | freebsd | 7.1 | Yes |
Operating System | freebsd | freebsd | 7.1 | Yes |
Operating System | freebsd | freebsd | 7.1 | Yes |
Operating System | freebsd | freebsd | 7.1 | Yes |
Operating System | freebsd | freebsd | 7.1 | Yes |
Operating System | freebsd | freebsd | 7.1 | Yes |
Operating System | freebsd | freebsd | 7.2 | Yes |
Operating System | freebsd | freebsd | 7.2 | Yes |
Operating System | freebsd | freebsd | 7.2 | Yes |
Operating System | freebsd | freebsd | 8.0 | Yes |
Operating System | freebsd | freebsd | 8.1-prerelease | Yes |
Application | nrl | opie | ≤ 2.4.1 | Yes |
Application | nrl | opie | 2.2 | Yes |
Application | nrl | opie | 2.3 | Yes |
Application | nrl | opie | 2.4 | Yes |
Application | nrl | opie | 2.10 | Yes |
Application | nrl | opie | 2.11 | Yes |
Application | nrl | opie | 2.21 | Yes |
Application | nrl | opie | 2.22 | Yes |
Application | nrl | opie | 2.32 | Yes |