PT-2010-1253 · None · Pyftpdlib

Publicado

2010-10-19

·

Atualizado

2022-05-17

·

CVE-2008-7264

CVSS v4.0

5.3

Média

VetorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions pyftpdlib versions prior to 0.5.0
Description The issue allows remote authenticated users to cause a denial of service, leading to file descriptor exhaustion and daemon outage. This is achieved by sending a QUIT command during a disallowed data-transfer attempt, specifically exploiting the ftp QUIT function in ftpserver.py.
Recommendations For versions prior to 0.5.0, update to version 0.5.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the ftp QUIT function in ftpserver.py to minimize the risk of exploitation.

Exploit

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-7264
GHSA-8P2C-FGHC-9HJ4
PYSEC-2010-6

Produtos afetados

Pyftpdlib