LWN.net Logo

wu-ftpd: missing input sanitizing

Package(s):wu-ftpd CVE #(s):CAN-2005-0256
Created:April 4, 2005 Updated:April 6, 2005
Description: The wu_fnmatch function in wu_fnmatch.c for wu-fptd 2.6.1 and 2.6.2 allows remote attackers to cause a denial of service (CPU exhaustion by recursion) via a glob pattern with a large number of * (wildcard) characters, as demonstrated using the dir command.
Alerts:
Debian DSA-705-1 2005-04-04

(Log in to post comments)

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds