PT-2011-2335 · Pure Ftpd+1 · Pure-Ftpd+1
Publicado
2011-05-24
·
Atualizado
2024-06-15
·
CVE-2011-0418
CVSS v2.0
4.0
Média
| Vetor | AV:N/AC:L/Au:S/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Pure-FTPd versions prior to 1.0.32
NetBSD 5.1
Description
The issue is related to the glob implementation, which does not properly expand expressions containing curly brackets. This allows remote authenticated users to cause a denial of service, specifically memory consumption, by sending a crafted FTP STAT command.
Recommendations
For Pure-FTPd versions prior to 1.0.32, update to version 1.0.32 or later to resolve the issue.
For NetBSD 5.1, there is no information about a newer version that contains a fix for this issue.
Exploit
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Netbsd
Pure-Ftpd