The vsf_filename_passes_filter function in ls.c in vsftpd before 2.3.3 allows remote authenticated users to cause a denial of service (CPU consumption and process slot exhaustion) via crafted glob expressions in STAT commands in multiple FTP sessions, a different vulnerability than CVE-2010-2632.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Canonical
Subscribe
|
Ubuntu Linux
Subscribe
|
|
Debian
Subscribe
|
Debian Linux
Subscribe
|
|
Fedoraproject
Subscribe
|
Fedora
Subscribe
|
|
Opensuse
Subscribe
|
Opensuse
Subscribe
|
|
Redhat
Subscribe
|
Enterprise Linux
Subscribe
|
|
Suse
Subscribe
|
Linux Enterprise Server
Subscribe
|
|
Vsftpd Project
Subscribe
|
Vsftpd
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-2305-1 | vsftpd security update |
Ubuntu USN |
USN-1098-1 | vsftpd vulnerability |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: certcc
Published:
Updated: 2024-08-06T22:05:53.406Z
Reserved: 2011-02-03T00:00:00.000Z
Link: CVE-2011-0762
No data.
Status : Deferred
Published: 2011-03-02T20:00:01.770
Modified: 2025-04-11T00:51:21.963
Link: CVE-2011-0762
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
Ubuntu USN