CVE-2011-0762
The vsf_filename_passes_filter function in ls.c in vsftpd before 2.3.3 allows remote authenticated users to cause a denial of service (CPU consumption and process slot exhaustion) via crafted glob expressions in STAT commands in multiple FTP sessions, a…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 73.9%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
The vsf_filename_passes_filter function in ls.c in vsftpd before 2.3.3 allows remote authenticated users to cause a denial of service (CPU consumption and process slot exhaustion) via crafted glob expressions in STAT commands in multiple FTP sessions, a different vulnerability than CVE-2010-2632.
- CVSS 2.0
- 4.0 MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
- EPSS
- 73.95% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-400
- Affected
- vsftpd project/vsftpd · canonical/ubuntu linux · fedoraproject/fedora · debian/debian linux · opensuse/opensuse · suse/linux enterprise server
- Source
- cret@cert.org
References
- ftp://vsftpd.beasts.org/users/cevans/untar/vsftpd-2.3.4/ChangelogBroken Link
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=622741Issue Tracking, Third Party Advisory
- http://cxib.net/stuff/vspoc232.cBroken Link
- http://jvn.jp/en/jp/JVN37417423/index.htmlThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2011-March/055881.htmlThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2011-March/055882.htmlThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2011-March/055957.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2011-05/msg00005.htmlMailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=133226187115472&w=2Issue Tracking, Third Party Advisory
- http://securityreason.com/achievement_securityalert/95Exploit, Third Party Advisory
- http://securityreason.com/securityalert/8109Exploit, Third Party Advisory
- http://www.debian.org/security/2011/dsa-2305Third Party Advisory
- http://www.exploit-db.com/exploits/16270Exploit, Third Party Advisory, VDB Entry
- http://www.kb.cert.org/vuls/id/590604Broken Link
- http://www.mandriva.com/security/advisories?name=MDVSA-2011:049Third Party Advisory
- http://www.redhat.com/support/errata/RHSA-2011-0337.htmlThird Party Advisory
- http://www.securityfocus.com/archive/1/516748/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/46617Exploit, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1025186Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-1098-1Third Party Advisory
- http://www.vupen.com/english/advisories/2011/0547Third Party Advisory
- http://www.vupen.com/english/advisories/2011/0639Third Party Advisory
- http://www.vupen.com/english/advisories/2011/0668Third Party Advisory
- http://www.vupen.com/english/advisories/2011/0713Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/65873Third Party Advisory, VDB Entry
- ftp://vsftpd.beasts.org/users/cevans/untar/vsftpd-2.3.4/ChangelogBroken Link
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=622741Issue Tracking, Third Party Advisory
- http://cxib.net/stuff/vspoc232.cBroken Link
- http://jvn.jp/en/jp/JVN37417423/index.htmlThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2011-March/055881.htmlThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.