CVE-2007-6263
Estado: ModificadaAlta (9.3)—
The dataconn function in ftpd.c in netkit ftpd (netkit-ftpd) 0.17, when certain modifications to support SSL have been introduced, calls fclose on an uninitialized file stream, which allows remote attackers to cause a denial of service (daemon crash) and possibly have unspecified other impact via some types of FTP over SSL protocol behavior, as demonstrated by breaking a passive FTP DATA connection in a way that triggers an error in the server's SSL_accept function. NOTE: the netkit ftp issue is covered by CVE-2007-5769.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C
- Puntuación base: 9.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 2.48%
- Percentil entre todas las CVEs puntuadas: 84
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-20
Referencias
- http://bugs.gentoo.org/show_bug.cgi?id=199206
- http://marc.info/?l=full-disclosure&m=119704348003382&w=2
- http://osvdb.org/41191
- http://secunia.com/advisories/28697
- http://www.gentoo.org/security/en/glsa/glsa-200801-17.xml
- http://www.securityfocus.com/bid/26763
- http://bugs.gentoo.org/show_bug.cgi?id=199206
- http://marc.info/?l=full-disclosure&m=119704348003382&w=2
- http://osvdb.org/41191
- http://secunia.com/advisories/28697
- http://www.gentoo.org/security/en/glsa/glsa-200801-17.xml
- http://www.securityfocus.com/bid/26763
JSON original (NVD)
Mostrar
{
"id": "CVE-2007-6263",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 9.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "MEDIUM",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": true,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2007-12-06T15:46:00.000",
"references": [
{
"url": "http://bugs.gentoo.org/show_bug.cgi?id=199206",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "http://marc.info/?l=full-disclosure&m=119704348003382&w=2",
"source": "cve@mitre.org"
},
{
"url": "http://osvdb.org/41191",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/28697",
"source": "cve@mitre.org"
},
{
"url": "http://www.gentoo.org/security/en/glsa/glsa-200801-17.xml",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/26763",
"source": "cve@mitre.org"
},
{
"url": "http://bugs.gentoo.org/show_bug.cgi?id=199206",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://marc.info/?l=full-disclosure&m=119704348003382&w=2",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://osvdb.org/41191",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/28697",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.gentoo.org/security/en/glsa/glsa-200801-17.xml",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/26763",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The dataconn function in ftpd.c in netkit ftpd (netkit-ftpd) 0.17, when certain modifications to support SSL have been introduced, calls fclose on an uninitialized file stream, which allows remote attackers to cause a denial of service (daemon crash) and possibly have unspecified other impact via some types of FTP over SSL protocol behavior, as demonstrated by breaking a passive FTP DATA connection in a way that triggers an error in the server's SSL_accept function. NOTE: the netkit ftp issue is covered by CVE-2007-5769."
},
{
"lang": "es",
"value": "La función dataconn en ftpd.c de netkit ftpd (netkit-ftpd) 0.17, al introducir ciertas modificaciones para el soporte SSL, llama a la función fclose sobre un flujo de fichero no inicializado, lo cual permite a atacantes remotos provocar una denegación de servicio (caída del demonio) y posiblemente tener algún otro impacto desconocido mediante ciertos comportamientos de FTP sobre SSL, como ha sido demostrado rompiendo una conexión pasiva FTP DATA de forma que provoca un error en la función SSL_accept del servidor. NOTA: el asunto de netkit ftp está cubierto en CVE-2007-5769."
}
],
"lastModified": "2026-06-16T22:47:42.700",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:netkit-ftp:netkit_ftp:0.17:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AB45F7C8-CDB0-40EE-A26E-12CA9577EDFB"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}