|
|
| |
|
| |
vsftpd: denial of service
| Package(s): | vsftpd |
CVE #(s): | CVE-2011-2189
|
| Created: | September 19, 2011 |
Updated: | December 7, 2011 |
| Description: |
From the Debian advisory:
Maksymilian Arciemowicz discovered that vsftpd is incorrectly handling
certain glob expressions in STAT commands. This allows a remote authenticated attacker to conduct denial of service attacks (excessive CPU and process slot exhaustion) via crafted STAT commands. |
| Alerts: |
|
( Log in to post comments)
|
|
|