Vulnerability record · CVE-2003-0466 · published 27 August 2003
CVE-2003-0466: wu-ftpd fb_realpath off-by-one buffer overflow enables remote code execution
Redhat · Wu Ftpd
An off-by-one error in the fb_realpath() function, derived from the BSD realpath implementation, causes a buffer overflow when a pathname of length MAXPATHLEN+1 is processed. In wu-ftpd 2.5.0 through 2.6.2 this is reachable through FTP commands such as STOR, RETR, APPE, DELE, MKD, RMD, STOU and RNTO. The flaw matters because it is remotely reachable without authentication and can lead to arbitrary code execution on the FTP server.
Description
Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code, as demonstrated in wu-ftpd 2.5.0 through 2.6.2 via commands that cause pathnames of length MAXPATHLEN+1 to trigger a buffer overflow, including (1) STOR, (2) RETR, (3) APPE, (4) DELE, (5) MKD, (6) RMD, (7) STOU, or (8) RNTO.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or interaction required, very high EPSS, and public exploit references make this a critical remote code execution risk on unpatched wu-ftpd.
What it is
An off-by-one error in the fb_realpath() function, derived from the BSD realpath implementation, causes a buffer overflow when a pathname of length MAXPATHLEN+1 is processed. In wu-ftpd 2.5.0 through 2.6.2 this is reachable through FTP commands such as STOR, RETR, APPE, DELE, MKD, RMD, STOU and RNTO. The flaw matters because it is remotely reachable without authentication and can lead to arbitrary code execution on the FTP server.
Impact
A remote attacker can overflow the buffer and execute arbitrary code with the privileges of the FTP service, typically root on wu-ftpd deployments. This gives full control of the host rather than just file access.
Attack surface
Reached over the network through the FTP service by sending commands containing an overlong pathname; the CVSS vector shows no privileges or user interaction required. Any client able to connect to the FTP port can attempt it.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.781, 99.55th percentile) and multiple references carry Exploit tags, indicating public exploit material exists. No ransomware group usage is documented in the record.
What to do
- Apply the vendor patch or upgrade wu-ftpd to a fixed release; Red Hat, Debian, Mandriva, Novell, Sun and BSD advisories in the references list fixes.
- If wu-ftpd cannot be patched, disable or restrict the FTP service and block port 21 from untrusted networks.
- Replace wu-ftpd with a maintained FTP daemon that is not affected by this fb_realpath flaw.
- Run the FTP service with least privilege and in a confined environment so a successful overflow does not yield root.
- Monitor vendor advisories for the affected BSD and Solaris platforms, which share the derived realpath code.
Detection
- Inspect FTP server logs for commands (STOR, RETR, APPE, DELE, MKD, RMD, STOU, RNTO) containing pathnames near or above MAXPATHLEN length.
- Alert on FTP sessions that send unusually long path arguments or malformed command sequences.
- Watch for crashes or restarts of the FTP daemon, which can indicate a failed overflow attempt.
- Monitor for unexpected child processes or outbound connections spawned by the FTP service.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
8 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2003-0466 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2003-0466), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.