Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2010-1938

Off-by-one error in the __opiereadrec function in readrec.c in libopie in OPIE 2.4.1-test1 and earlier, as used on FreeBSD 6.4 through 8.1-PRERELEASE and other platforms, allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a long username, as demonstrated by a long USER command to the FreeBSD 8.0 ftpd.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.645
EPSS Ranking 98.4%
CVSS Severity
CVSS v2 Score 9.3
References
Products affected by CVE-2010-1938
  • Nrl » Opie » Version: Any
    cpe:2.3:a:nrl:opie:*
  • Nrl » Opie » Version: 2.10
    cpe:2.3:a:nrl:opie:2.10
  • Nrl » Opie » Version: 2.11
    cpe:2.3:a:nrl:opie:2.11
  • Nrl » Opie » Version: 2.2
    cpe:2.3:a:nrl:opie:2.2
  • Nrl » Opie » Version: 2.21
    cpe:2.3:a:nrl:opie:2.21
  • Nrl » Opie » Version: 2.22
    cpe:2.3:a:nrl:opie:2.22
  • Nrl » Opie » Version: 2.3
    cpe:2.3:a:nrl:opie:2.3
  • Nrl » Opie » Version: 2.32
    cpe:2.3:a:nrl:opie:2.32
  • Nrl » Opie » Version: 2.4
    cpe:2.3:a:nrl:opie:2.4
  • Freebsd » Freebsd » Version: 6
    cpe:2.3:o:freebsd:freebsd:6
  • Freebsd » Freebsd » Version: 6.4
    cpe:2.3:o:freebsd:freebsd:6.4
  • Freebsd » Freebsd » Version: 7.0
    cpe:2.3:o:freebsd:freebsd:7.0
  • Freebsd » Freebsd » Version: 7.0-release
    cpe:2.3:o:freebsd:freebsd:7.0-release
  • Freebsd » Freebsd » Version: 7.0_beta4
    cpe:2.3:o:freebsd:freebsd:7.0_beta4
  • Freebsd » Freebsd » Version: 7.0_releng
    cpe:2.3:o:freebsd:freebsd:7.0_releng
  • Freebsd » Freebsd » Version: 7.1
    cpe:2.3:o:freebsd:freebsd:7.1
  • Freebsd » Freebsd » Version: 7.2
    cpe:2.3:o:freebsd:freebsd:7.2
  • Freebsd » Freebsd » Version: 8.0
    cpe:2.3:o:freebsd:freebsd:8.0
  • Freebsd » Freebsd » Version: 8.1-prerelease
    cpe:2.3:o:freebsd:freebsd:8.1-prerelease


Contact Us

Shodan ® - All rights reserved