Back

CVE-2004-2523

Format string vulnerability in the msg command (cat_message function in msg.c) in OpenFTPD 0.30.2 and earlier allows remote authenticated users to execute arbitrary code via format string specifiers in the message argument.

Published: Dec 31, 2004 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (4)

Vendor Product Version
openftpd openftpd_ftp_server *
openftpd openftpd_ftp_server 0.29.4
openftpd openftpd_ftp_server 0.30
openftpd openftpd_ftp_server 0.30.1

GitHub Security Advisory GHSA-7gj2-q7q5-28j5

Format string vulnerability in the msg command (cat_message function in msg.c) in OpenFTPD 0.30.2...

Risk Scores

CVSS Score 6.5 / 10
EPSS Score 5.40%

Top 8% most likely to be exploited

Threat Score 27.6 / 100

Data Sources

NVD EPSS GitHub