← Vulnerability feed

Vulnerability record · CVE-2001-0550 · published 30 November 2001

CVE-2001-0550: wu-ftpd glob handling flaw allows remote command execution

DDavid Madore · Ftpd Bsd

wu-ftpd 2.6.1 fails to properly handle a "~{" argument passed to FTP commands such as CWD, because the glob function (ftpglob) mishandles it. A remote attacker can therefore execute arbitrary commands on the FTP server. The flaw is remotely reachable and rated HIGH (CVSS 2.0 7.5), making it a serious risk for any exposed wu-ftpd service.

7.5 CVSS 2.0 High EPSS 75% · top 0.5%
7.5CVSS 2.0 base score
75%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
28References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

wu-ftpd 2.6.1 allows remote attackers to execute arbitrary commands via a "~{" argument to commands such as CWD, which is not properly handled by the glob function (ftpglob).

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityRemote, unauthenticated command execution with public exploit code and very high EPSS, though the product is legacy and not in KEV.

What it is

wu-ftpd 2.6.1 fails to properly handle a "~{" argument passed to FTP commands such as CWD, because the glob function (ftpglob) mishandles it. A remote attacker can therefore execute arbitrary commands on the FTP server. The flaw is remotely reachable and rated HIGH (CVSS 2.0 7.5), making it a serious risk for any exposed wu-ftpd service.

Impact

An attacker gains arbitrary command execution on the FTP server, typically in the context of the ftpd process, which can lead to full host compromise. No confidentiality, integrity or availability impact is excluded by the vector; all three are partial.

Attack surface

Reached over the network via the FTP service by sending a crafted "~{" argument to commands such as CWD. The CVSS vector (AV:N/AC:L/Au:N) indicates no authentication and no user interaction are required.

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.74762, 99.5th percentile) and a SecurityFocus reference is tagged Exploit, indicating public exploit code exists.

What to do

  • Patch or upgrade wu-ftpd to a fixed release per the vendor advisories (Red Hat RHSA-2001-157, Caldera CSSA-2001-041, Debian DSA-087, CERT CA-2001-33).
  • If patching is not possible, disable or restrict anonymous and untrusted FTP access, or replace wu-ftpd with a maintained FTP server.
  • Block or filter FTP traffic from untrusted networks at the perimeter until the service is patched.
  • Audit the FTP service account's privileges and file system access to limit the blast radius of command execution.

Detection

  • Inspect FTP command logs for arguments containing "~{" or unusual glob metacharacters in CWD and similar commands.
  • Monitor for unexpected child processes or shell activity spawned by the ftpd process.
  • Alert on FTP sessions from unexpected source addresses or with anomalous command sequences.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000442
http://download.immunix.org/ImmunixOS/7.0/updates/IMNX-2001-70-036-01
http://marc.info/?l=bugtraq&m=100700363414799&w=2
http://www.caldera.com/support/security/advisories/CSSA-2001-041.0.txt PatchVendor Advisory
http://www.cert.org/advisories/CA-2001-33.html PatchThird Party AdvisoryUS Government Resource
http://www.debian.org/security/2001/dsa-087
http://www.kb.cert.org/vuls/id/886083 PatchThird Party AdvisoryUS Government Resource
http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-090.php3
http://www.novell.com/linux/security/advisories/2001_043_wuftpd_txt.html
http://www.redhat.com/support/errata/RHSA-2001-157.html PatchVendor Advisory
http://www.securityfocus.com/archive/82/180823
http://www.securityfocus.com/bid/3581 ExploitPatchVendor Advisory
http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX0107-162
https://exchange.xforce.ibmcloud.com/vulnerabilities/7611
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000442
http://download.immunix.org/ImmunixOS/7.0/updates/IMNX-2001-70-036-01
http://marc.info/?l=bugtraq&m=100700363414799&w=2
http://www.caldera.com/support/security/advisories/CSSA-2001-041.0.txt PatchVendor Advisory
http://www.cert.org/advisories/CA-2001-33.html PatchThird Party AdvisoryUS Government Resource
http://www.debian.org/security/2001/dsa-087
http://www.kb.cert.org/vuls/id/886083 PatchThird Party AdvisoryUS Government Resource
http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-090.php3
http://www.novell.com/linux/security/advisories/2001_043_wuftpd_txt.html
http://www.redhat.com/support/errata/RHSA-2001-157.html PatchVendor Advisory
http://www.securityfocus.com/archive/82/180823
http://www.securityfocus.com/bid/3581 ExploitPatchVendor Advisory
http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX0107-162
https://exchange.xforce.ibmcloud.com/vulnerabilities/7611

Track CVE-2001-0550 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2004-0185Washington university wu-ftpd vulnerabilityBuffer overflow in the skey_challenge function in ftpd.c for wu-ftp daemon (wu-ftpd) 2.6.2 allows remote attackers to cause a denial of service and p…EPSS 7.4%10.0CVE-2001-0187Washington university wu-ftpd vulnerabilityFormat string vulnerability in wu-ftp 2.6.1 and earlier, when running with debug mode enabled, allows remote attackers to execute arbitrary commands …EPSS 5.7%10.0CVE-2001-0053David madore ftpd-bsd vulnerabilityOne-byte buffer overflow in replydirname function in BSD-based ftpd allows remote attackers to gain root privileges.EPSS 18%10.0CVE-1999-0878Beroftpd vulnerabilityBuffer overflow in WU-FTPD and related FTP servers allows remote attackers to gain root privileges via MAPPING_CHDIR.EPSS 2.2%10.0CVE-1999-0368Proftpd project proftpd vulnerabilityBuffer overflows in wuarchive ftpd (wu-ftpd) and ProFTPD lead to remote root access, a.k.a. palmetto.EPSS 40%10.0CVE-1999-0080Washington university wu-ftpd vulnerabilityCertain configurations of wu-ftp FTP server 2.4 use a _PATH_EXECPATH setting to a directory with dangerous commands, such as /bin, which allows remot…EPSS 4.0%9.3CVE-2003-1327Washington university wu-ftpd vulnerabilityBuffer overflow in the SockPrintf function in wu-ftpd 2.6.2 and earlier, when compiled with MAIL_ADMIN option enabled on a system that supports very …EPSS 3.3%7.8CVE-2003-1329Washington university wu-ftpd vulnerabilityftpd.c in wu-ftpd 2.6.2, when running on "operating systems that only allow one non-connected socket bound to the same local address," does not close…EPSS 1.3%

Source: NIST National Vulnerability Database (record CVE-2001-0550), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.