Back
CVE-2005-0958
Format string vulnerability in the log_do function in log.c for YepYep mtftpd 0.0.3, when the statistics option is enabled, allows remote attackers to execute arbitrary code via the CWD command.
Published: May 2, 2005
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (3)
| Vendor | Product | Version |
|---|---|---|
| yepyep | mtftpd | 0.1a |
| yepyep | mtftpd | 0.2 |
| yepyep | mtftpd | 0.3 |
GitHub Security Advisory GHSA-cmjf-37pm-69r5
Format string vulnerability in the log_do function in log.c for YepYep mtftpd 0.0.3, when the...
References (8)
- http://unl0ck.org/files/papers/mtftpd.txt Exploit, URL Repurposed
- http://www.securiteam.com/exploits/5KP0W0AF5K.html Exploit
- http://www.securityfocus.com/bid/12947 Exploit
- http://www.tripbit.org/advisories/TA-040305.txt
- http://unl0ck.org/files/papers/mtftpd.txt Exploit, URL Repurposed
- http://www.securiteam.com/exploits/5KP0W0AF5K.html Exploit
- http://www.securityfocus.com/bid/12947 Exploit
- http://www.tripbit.org/advisories/TA-040305.txt
Risk Scores
CVSS Score
7.5 / 10
EPSS Score
4.43%
Top 9% most likely to be exploited
Threat Score
31.3 / 100
Data Sources
NVD
EPSS
GitHub