|
|
Log in / Subscribe / Register

vsftpd: denial of service

Package(s):vsftpd CVE #(s):CVE-2011-0762
Created:March 10, 2011 Updated:October 11, 2011
Description: From the CVE entry:

The vsf_filename_passes_filter function in ls.c in vsftpd before 2.3.3 allows remote authenticated users to cause a denial of service (CPU consumption and process slot exhaustion) via crafted glob expressions in STAT commands in multiple FTP sessions, a different vulnerability than CVE-2010-2632.

Alerts:
Gentoo 201110-07 vsftpd 2011-10-10
Debian DSA-2305-1 vsftpd 2011-09-19
CentOS CESA-2011:0337 vsftpd 2011-04-14
Ubuntu USN-1098-1 vsftpd 2011-03-29
SUSE SUSE-SR:2011:009 mailman, openssl, tgt, rsync, vsftpd, libzip1/libzip-devel, otrs, libtiff, kdelibs4, libwebkit, libpython2_6-1_0, perl, pure-ftpd, collectd, vino, aaa_base, exim 2011-05-17
openSUSE openSUSE-SU-2011:0435-1 vsftp 2011-05-06
Mandriva MDVSA-2011:049 vsftpd 2011-03-21
Fedora FEDORA-2011-2615 vsftpd 2011-03-04
Fedora FEDORA-2011-2590 vsftpd 2011-03-04
CentOS CESA-2011:0337 vsftpd 2011-03-10
Red Hat RHSA-2011:0337-01 vsftpd 2011-03-09

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds