CVE-2003-0854 describes a local denial-of-service vulnerability in the 'ls' utility, part of GNU fileutils and coreutils packages, which can be remotely triggered through applications like wu-ftpd. An attacker can exploit this by providing a large '-w' value, leading to excessive memory consumption. This vulnerability has a low severity CVSS score of 2.1, indicating a local attack vector with low complexity and a potential impact of partial availability loss. While an ExploitDB entry exists for a remote denial-of-service against WU-FTPD, there is no evidence of active exploitation, Metasploit modules, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.0CPE matchmatch criteria | cpe:2.3:a:gnu:fileutils:4.0:*:*:*:*:*:*:* | ||
4.0.36CPE matchmatch criteria | cpe:2.3:a:gnu:fileutils:4.0.36:*:*:*:*:*:*:* | ||
4.1CPE matchmatch criteria | cpe:2.3:a:gnu:fileutils:4.1:*:*:*:*:*:*:* | ||
4.1.6CPE matchmatch criteria | cpe:2.3:a:gnu:fileutils:4.1.6:*:*:*:*:*:*:* | ||
4.1.7CPE matchmatch criteria | cpe:2.3:a:gnu:fileutils:4.1.7:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:N/I:N/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.