4

CVE-2011-0762

Exploit

The vsf_filename_passes_filter function in ls.c in vsftpd before 2.3.3 allows remote authenticated users to cause a denial of service (CPU consumption and process slot exhaustion) via crafted glob expressions in STAT commands in multiple FTP sessions, a different vulnerability than CVE-2010-2632.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Vsftpd ProjectVsftpd Version < 2.3.3
CanonicalUbuntu Linux Version6.06
CanonicalUbuntu Linux Version8.04 SwEdition-
CanonicalUbuntu Linux Version9.10
CanonicalUbuntu Linux Version10.04 SwEdition-
CanonicalUbuntu Linux Version10.10
FedoraprojectFedora Version13
FedoraprojectFedora Version14
FedoraprojectFedora Version15
DebianDebian Linux Version5.0
DebianDebian Linux Version6.0
DebianDebian Linux Version7.0
OpensuseOpensuse Version11.2
OpensuseOpensuse Version11.3
OpensuseOpensuse Version11.4
SuseLinux Enterprise Server Version10 Updatesp3 SwEdition-
SuseLinux Enterprise Server Version10 Updatesp4 SwEdition-
SuseLinux Enterprise Server Version11 Updatesp1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 52.11% 0.978
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4 8 2.9
AV:N/AC:L/Au:S/C:N/I:N/A:P
CWE-400 Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.

http://marc.info/?l=bugtraq&m=133226187115472&w=2
Third Party Advisory
Issue Tracking
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=622741
Third Party Advisory
Issue Tracking
http://securityreason.com/securityalert/8109
Third Party Advisory
Exploit
http://www.exploit-db.com/exploits/16270
Third Party Advisory
Exploit
VDB Entry
http://www.securityfocus.com/bid/46617
Third Party Advisory
Exploit
VDB Entry
http://www.securitytracker.com/id?1025186
Third Party Advisory
VDB Entry