An off-by-one error in the __opiereadrec function in readrec.c in libopie (OPIE) 2.4.1-test1 and earlier (as used by FreeBSD 6.4 through 8.1-PRERELEASE and other platforms) can be triggered by an overly long username. In FreeBSD, this is demonstrated via a long USER command to ftpd, leading to a stack-based overflow condition that can crash the daemon and, depending on platform/compiler protections and memory layout, may be exploitable for arbitrary code execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a Python exploit script (exploit.py) and a README.md file. The exploit targets CVE-2010-1938, an off-by-one vulnerability in the OPIE library used by some FTP servers. The script connects to a user-specified FTP server (default placeholders are present for IP and port), crafts a payload consisting of a buffer overflow (with a truncated reverse shell shellcode), and sends it in fragments as the FTP USER command to avoid detection and server crashes. After sending the payload, it issues a PASS command to trigger the vulnerability. The script iterates over several payload sizes to maximize the chance of successful exploitation. The README provides detailed usage instructions, requirements, and a description of the vulnerability and exploit process. The exploit is operational, with a basic shellcode payload, and is intended for penetration testing and research on vulnerable FTP servers. No hardcoded endpoints are present; the user must supply the target IP. The main attack vector is network-based, targeting the FTP service (port 21) on the victim server.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.