4

CVE-2008-7265

The pr_data_xfer function in ProFTPD before 1.3.2rc3 allows remote authenticated users to cause a denial of service (CPU consumption) via an ABOR command during a data transfer.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Proftpd ≫ Proftpd Update rc2 Version <= 1.3.2
Proftpd ≫ Proftpd Version 1.2.0
Proftpd ≫ Proftpd Version 1.2.0 Update pre10
Proftpd ≫ Proftpd Version 1.2.0 Update pre9
Proftpd ≫ Proftpd Version 1.2.0 Update rc1
Proftpd ≫ Proftpd Version 1.2.0 Update rc2
Proftpd ≫ Proftpd Version 1.2.0 Update rc3
Proftpd ≫ Proftpd Version 1.2.1
Proftpd ≫ Proftpd Version 1.2.2
Proftpd ≫ Proftpd Version 1.2.2 Update rc1
Proftpd ≫ Proftpd Version 1.2.2 Update rc2
Proftpd ≫ Proftpd Version 1.2.2 Update rc3
Proftpd ≫ Proftpd Version 1.2.3
Proftpd ≫ Proftpd Version 1.2.4
Proftpd ≫ Proftpd Version 1.2.5
Proftpd ≫ Proftpd Version 1.2.5 Update rc1
Proftpd ≫ Proftpd Version 1.2.5 Update rc2
Proftpd ≫ Proftpd Version 1.2.5 Update rc3
Proftpd ≫ Proftpd Version 1.2.6
Proftpd ≫ Proftpd Version 1.2.6 Update rc1
Proftpd ≫ Proftpd Version 1.2.6 Update rc2
Proftpd ≫ Proftpd Version 1.2.7
Proftpd ≫ Proftpd Version 1.2.7 Update rc1
Proftpd ≫ Proftpd Version 1.2.7 Update rc2
Proftpd ≫ Proftpd Version 1.2.7 Update rc3
Proftpd ≫ Proftpd Version 1.2.8
Proftpd ≫ Proftpd Version 1.2.8 Update rc1
Proftpd ≫ Proftpd Version 1.2.8 Update rc2
Proftpd ≫ Proftpd Version 1.2.9
Proftpd ≫ Proftpd Version 1.2.9 Update rc1
Proftpd ≫ Proftpd Version 1.2.9 Update rc2
Proftpd ≫ Proftpd Version 1.2.9 Update rc3
Proftpd ≫ Proftpd Version 1.2.10
Proftpd ≫ Proftpd Version 1.2.10 Update rc1
Proftpd ≫ Proftpd Version 1.2.10 Update rc2
Proftpd ≫ Proftpd Version 1.2.10 Update rc3
Proftpd ≫ Proftpd Version 1.3.0
Proftpd ≫ Proftpd Version 1.3.0 Update a
Proftpd ≫ Proftpd Version 1.3.0 Update rc1
Proftpd ≫ Proftpd Version 1.3.0 Update rc2
Proftpd ≫ Proftpd Version 1.3.0 Update rc3
Proftpd ≫ Proftpd Version 1.3.0 Update rc4
Proftpd ≫ Proftpd Version 1.3.0 Update rc5
Proftpd ≫ Proftpd Version 1.3.1
Proftpd ≫ Proftpd Version 1.3.1 Update rc1
Proftpd ≫ Proftpd Version 1.3.1 Update rc2
Proftpd ≫ Proftpd Version 1.3.1 Update rc3
Proftpd ≫ Proftpd Version 1.3.2 Update rc1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.2% 0.865
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4 8 2.9
AV:N/AC:L/Au:S/C:N/I:N/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://bugs.proftpd.org/show_bug.cgi?id=3131
Patch
http://www.debian.org/security/2011/dsa-2191