CVE-2001-0187 describes a critical format string vulnerability in wu-ftpd versions 2.6.1 and earlier, specifically when the FTP server is running with debug mode enabled. This flaw allows unauthenticated remote attackers to execute arbitrary commands by crafting a malicious argument within a PASV port assignment. With a CVSS score of 10.0 (HIGH), the vulnerability presents a severe risk due to its network-based attack vector, low complexity, and complete compromise of confidentiality, integrity, and availability. While not listed on the KEV catalog or Hot List, public exploit code exists, indicating its potential for exploitation, though it currently lacks significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.4.1CPE matchmatch criteria | cpe:2.3:a:washington_university:wu-ftpd:2.4.1:*:*:*:*:*:*:* | ||
2.4.2_beta9CPE matchmatch criteria | cpe:2.3:a:washington_university:wu-ftpd:2.4.2_beta9:*:academ:*:*:*:*:* | ||
2.4.2_beta18CPE matchmatch criteria | cpe:2.3:a:washington_university:wu-ftpd:2.4.2_beta18:*:academ:*:*:*:*:* | ||
2.4.2_beta18_vr4CPE matchmatch criteria | cpe:2.3:a:washington_university:wu-ftpd:2.4.2_beta18_vr4:*:*:*:*:*:*:* | ||
2.4.2_beta18_vr5CPE matchmatch criteria | cpe:2.3:a:washington_university:wu-ftpd:2.4.2_beta18_vr5:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.