CVE-2002-2245

ftpd in NetBSD 1.5 through 1.5.3 and 1.6 does not properly quote a digit in response to a STAT command for a filename that contains a carriage return followed by a digit, which can cause firewalls and other intermediary devices to lose proper track of the FTP session.

Scoring

CVSS base score
0.01
EPSS probability
0.27%
Published
2007-10-14
Last modified
2026-03-16

Affected products

Markdown version · Browse all CVEs