LWN.net Logo

vsftpd: denial of service

Package(s):vsftpd CVE #(s):CVE-2011-2189
Created:September 19, 2011 Updated:December 7, 2011
Description: From the Debian advisory:

Maksymilian Arciemowicz discovered that vsftpd is incorrectly handling certain glob expressions in STAT commands. This allows a remote authenticated attacker to conduct denial of service attacks (excessive CPU and process slot exhaustion) via crafted STAT commands.

Alerts:
Ubuntu USN-1288-1 2011-12-07
Debian DSA-2305-1 2011-09-19

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds