4

CVE-2011-0418

Exploit

The glob implementation in Pure-FTPd before 1.0.32, and in libc in NetBSD 5.1, does not properly expand expressions containing curly brackets, which allows remote authenticated users to cause a denial of service (memory consumption) via a crafted FTP STAT command.

Data is provided by the National Vulnerability Database (NVD)
PureftpdPure-ftpd Version <= 1.0.31
PureftpdPure-ftpd Version0.90
PureftpdPure-ftpd Version0.91
PureftpdPure-ftpd Version0.92
PureftpdPure-ftpd Version0.93
PureftpdPure-ftpd Version0.94
PureftpdPure-ftpd Version0.95
PureftpdPure-ftpd Version0.95-pre1
PureftpdPure-ftpd Version0.95-pre2
PureftpdPure-ftpd Version0.95-pre3
PureftpdPure-ftpd Version0.95-pre4
PureftpdPure-ftpd Version0.95.1
PureftpdPure-ftpd Version0.95.2
PureftpdPure-ftpd Version0.96
PureftpdPure-ftpd Version0.96.1
PureftpdPure-ftpd Version0.96pre1
PureftpdPure-ftpd Version0.97-final
PureftpdPure-ftpd Version0.97.1
PureftpdPure-ftpd Version0.97.2
PureftpdPure-ftpd Version0.97.3
PureftpdPure-ftpd Version0.97.4
PureftpdPure-ftpd Version0.97.5
PureftpdPure-ftpd Version0.97.6
PureftpdPure-ftpd Version0.97.7
PureftpdPure-ftpd Version0.97.7pre1
PureftpdPure-ftpd Version0.97.7pre2
PureftpdPure-ftpd Version0.97.7pre3
PureftpdPure-ftpd Version0.97pre1
PureftpdPure-ftpd Version0.97pre2
PureftpdPure-ftpd Version0.97pre3
PureftpdPure-ftpd Version0.97pre4
PureftpdPure-ftpd Version0.97pre5
PureftpdPure-ftpd Version0.98-final
PureftpdPure-ftpd Version0.98.1
PureftpdPure-ftpd Version0.98.2
PureftpdPure-ftpd Version0.98.2a
PureftpdPure-ftpd Version0.98.3
PureftpdPure-ftpd Version0.98.4
PureftpdPure-ftpd Version0.98.5
PureftpdPure-ftpd Version0.98.6
PureftpdPure-ftpd Version0.98.7
PureftpdPure-ftpd Version0.98pre1
PureftpdPure-ftpd Version0.98pre2
PureftpdPure-ftpd Version0.99
PureftpdPure-ftpd Version0.99.1
PureftpdPure-ftpd Version0.99.1a
PureftpdPure-ftpd Version0.99.1b
PureftpdPure-ftpd Version0.99.2
PureftpdPure-ftpd Version0.99.2a
PureftpdPure-ftpd Version0.99.3
PureftpdPure-ftpd Version0.99.4
PureftpdPure-ftpd Version0.99.9
PureftpdPure-ftpd Version0.99a
PureftpdPure-ftpd Version0.99b
PureftpdPure-ftpd Version0.99pre1
PureftpdPure-ftpd Version0.99pre2
PureftpdPure-ftpd Version1.0.0
PureftpdPure-ftpd Version1.0.1
PureftpdPure-ftpd Version1.0.2
PureftpdPure-ftpd Version1.0.3
PureftpdPure-ftpd Version1.0.4
PureftpdPure-ftpd Version1.0.5
PureftpdPure-ftpd Version1.0.6
PureftpdPure-ftpd Version1.0.7
PureftpdPure-ftpd Version1.0.8
PureftpdPure-ftpd Version1.0.9
PureftpdPure-ftpd Version1.0.10
PureftpdPure-ftpd Version1.0.11
PureftpdPure-ftpd Version1.0.12
PureftpdPure-ftpd Version1.0.13a
PureftpdPure-ftpd Version1.0.14
PureftpdPure-ftpd Version1.0.15
PureftpdPure-ftpd Version1.0.16a
PureftpdPure-ftpd Version1.0.16b
PureftpdPure-ftpd Version1.0.16c
PureftpdPure-ftpd Version1.0.17
PureftpdPure-ftpd Version1.0.17a
PureftpdPure-ftpd Version1.0.18
PureftpdPure-ftpd Version1.0.19
PureftpdPure-ftpd Version1.0.20
PureftpdPure-ftpd Version1.0.21
PureftpdPure-ftpd Version1.0.22
PureftpdPure-ftpd Version1.0.24
PureftpdPure-ftpd Version1.0.25
PureftpdPure-ftpd Version1.0.26
PureftpdPure-ftpd Version1.0.27
PureftpdPure-ftpd Version1.0.28
PureftpdPure-ftpd Version1.0.29
PureftpdPure-ftpd Version1.0.30
NetbsdNetbsd Version5.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 14.63% 0.942
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4 8 2.9
AV:N/AC:L/Au:S/C:N/I:N/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.