PT-2001-2117 · Glftpd · Glftpd
Published
2001-08-31
·
Updated
2008-09-05
·
CVE-2001-0965
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
glFTPD version 1.23
Description
The issue allows remote attackers to cause a denial of service, specifically CPU consumption, by sending a LIST command with an argument containing a large number of * (asterisk) characters.
Recommendations
For glFTPD version 1.23, consider restricting or limiting the use of the LIST command with arguments containing a large number of * characters until a patch is available. As a temporary workaround, implement input validation to prevent excessively long arguments in the LIST command.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Glftpd