« Volver al listado

CVE-2007-5622

Estado: ModificadaMedia (5)—

Double free vulnerability in the ftpprchild function in ftppr in 3proxy 0.5 through 0.5.3i allows remote attackers to cause a denial of service (daemon crash) via multiple OPEN commands to the FTP proxy.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2007-5622",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2007-10-29T21:46:00.000",
  "references": [
    {
      "url": "http://3proxy.ru/0.5.3j/Changelog.txt",
      "tags": [
        "Patch"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://bugs.gentoo.org/show_bug.cgi?id=196772",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://lists.grok.org.uk/pipermail/full-disclosure/2007-October/066985.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://osvdb.org/41870",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/27353",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/27607",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://security.gentoo.org/glsa/glsa-200711-13.xml",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/482697/100/0/threaded",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/26180",
      "tags": [
        "Patch"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/37401",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://3proxy.ru/0.5.3j/Changelog.txt",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://bugs.gentoo.org/show_bug.cgi?id=196772",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://lists.grok.org.uk/pipermail/full-disclosure/2007-October/066985.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://osvdb.org/41870",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/27353",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/27607",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://security.gentoo.org/glsa/glsa-200711-13.xml",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/482697/100/0/threaded",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/26180",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/37401",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-399"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Double free vulnerability in the ftpprchild function in ftppr in 3proxy 0.5 through 0.5.3i allows remote attackers to cause a denial of service (daemon crash) via multiple OPEN commands to the FTP proxy."
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad de doble liberación en la función ftpprchild en ftppr en 3proxy versiones 0.5 hasta 0.5.3i, permite a atacantes remotos causar una denegación de servicio (bloqueo de demonio) por medio de varios comandos OPEN en el proxy FTP."
    }
  ],
  "lastModified": "2026-06-16T22:46:30.863",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:3proxy:3proxy:0.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7086CA7A-6A00-41BD-B965-20BD49982A6D"
            },
            {
              "criteria": "cpe:2.3:a:3proxy:3proxy:0.5.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "87BC7A0B-1687-4DC6-B8BC-043D3A4588D4"
            },
            {
              "criteria": "cpe:2.3:a:3proxy:3proxy:0.5.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "597A63F7-0EB5-4E5E-A992-5F5A9F3D1496"
            },
            {
              "criteria": "cpe:2.3:a:3proxy:3proxy:0.5.3g:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1FB416A3-659D-4D88-9743-C09384B9DC7D"
            },
            {
              "criteria": "cpe:2.3:a:3proxy:3proxy:0.5.3h:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D2544C09-DAEE-4B52-8444-4ED7913DD16C"
            },
            {
              "criteria": "cpe:2.3:a:3proxy:3proxy:0.5.3i:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B5867137-517C-43DD-9680-DADFC6DCBD88"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}