← Back

CVE-2011-0762

Published: Mar 2, 2011Modified: Apr 29, 2026

JSON object

Loading...
4.0
Vector
AV:N/AC:L/Au:S/C:N/I:N/A:P
Exploitability: 8.0 / Impact: 2.9
Source: NVD

Description

The vsf_filename_passes_filter function in ls.c in vsftpd before 2.3.3 allows remote authenticated users to cause a denial of service (CPU consumption and process slot exhaustion) via crafted glob expressions in STAT commands in multiple FTP sessions, a different vulnerability than CVE-2010-2632.

Affected (19)

Show all products
Vsftpd
1 product
Ubuntu Linux
1 product
Fedora
1 product
Debian Linux
1 product
Opensuse
1 product
Linux Enterprise Server
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 2.3.3
Configuration B
5 vulnerable
Vulnerable SoftwareAffected Versions
Canonical
Version 10.04
Version 10.10
Version 6.06
Version 8.04
Version 9.10
Configuration C
3 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 13
Version 14
Version 15
Configuration D
3 vulnerable
Vulnerable SoftwareAffected Versions
Debian
Version 5.0
Version 6.0
Version 7.0
Configuration E
7 vulnerable
Vulnerable SoftwareAffected Versions
Opensuse
Version 11.2
Version 11.3
Version 11.4
Suse
Version 10 sp3
Version 10 sp4
Version 11 sp1
Version 9

References (50)

ftp://vsftpd.beasts.org/users/cevans/untar/vsftpd-2.3.4/Changelog (unsafe URL)
Source: cret@cert.org
Broken Link
Source: cret@cert.org
Issue TrackingThird Party Advisory
Source: cret@cert.org
Broken Link
Source: cret@cert.org
Third Party Advisory
Source: cret@cert.org
Mailing ListThird Party Advisory
Source: cret@cert.org
Issue TrackingThird Party Advisory
Source: cret@cert.org
ExploitThird Party Advisory
Source: cret@cert.org
ExploitThird Party Advisory
Source: cret@cert.org
Third Party Advisory
Source: cret@cert.org
ExploitThird Party AdvisoryVDB Entry
Source: cret@cert.org
Broken Link
Source: cret@cert.org
Third Party Advisory
Source: cret@cert.org
Third Party AdvisoryVDB Entry
Source: cret@cert.org
ExploitThird Party AdvisoryVDB Entry
Source: cret@cert.org
Third Party AdvisoryVDB Entry
Source: cret@cert.org
Third Party Advisory
Source: cret@cert.org
Third Party Advisory
Source: cret@cert.org
Third Party Advisory
Source: cret@cert.org
Third Party Advisory
Source: cret@cert.org
Third Party Advisory
Source: cret@cert.org
Third Party AdvisoryVDB Entry
ftp://vsftpd.beasts.org/users/cevans/untar/vsftpd-2.3.4/Changelog (unsafe URL)
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry

Timeline

No history available yet.