{ "schema_version": "1.4.0", "id": "GHSA-xch5-xh5p-whc7", "modified": "2022-05-01T18:41:12Z", "published": "2022-05-01T18:41:11Z", "aliases": [ "CVE-2007-6263" ], "details": "The dataconn function in ftpd.c in netkit ftpd (netkit-ftpd) 0.17, when certain modifications to support SSL have been introduced, calls fclose on an uninitialized file stream, which allows remote attackers to cause a denial of service (daemon crash) and possibly have unspecified other impact via some types of FTP over SSL protocol behavior, as demonstrated by breaking a passive FTP DATA connection in a way that triggers an error in the server's SSL_accept function. NOTE: the netkit ftp issue is covered by CVE-2007-5769.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2007-6263" }, { "type": "WEB", "url": "http://bugs.gentoo.org/show_bug.cgi?id=199206" }, { "type": "WEB", "url": "http://marc.info/?l=full-disclosure&m=119704348003382&w=2" }, { "type": "WEB", "url": "http://osvdb.org/41191" }, { "type": "WEB", "url": "http://secunia.com/advisories/28697" }, { "type": "WEB", "url": "http://www.gentoo.org/security/en/glsa/glsa-200801-17.xml" }, { "type": "WEB", "url": "http://www.securityfocus.com/bid/26763" } ], "database_specific": { "cwe_ids": [ "CWE-20" ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2007-12-06T15:46:00Z" } }