PT-2011-1043 · Vsftpd+1 · Vsftpd+1
Maksymilian Arciemowicz
·
Publicado
2011-03-02
·
Atualizado
2021-03-04
·
CVE-2011-0762
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
vsftpd versions prior to 2.3.3
Description
The issue allows remote authenticated users to cause a denial of service, consuming all CPU and exhausting process slots, through crafted glob expressions in STAT commands in multiple FTP sessions. This can lead to disruption of protected information availability. The exploitation can be carried out remotely.
Recommendations
For versions prior to 2.3.3, update to version 2.3.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the
vsf filename passes filter function in ls.c to minimize the risk of exploitation. Avoid using crafted glob expressions in STAT commands until the issue is resolved.Exploit
Correção
DoS
Resource Exhaustion
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Red Hat
Vsftpd