Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2011-0418

Опубликовано: 24 мая 2011
Источник: debian
EPSS Низкий

Описание

The glob implementation in Pure-FTPd before 1.0.32, and in libc in NetBSD 5.1, does not properly expand expressions containing curly brackets, which allows remote authenticated users to cause a denial of service (memory consumption) via a crafted FTP STAT command.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
pure-ftpdfixed1.0.32-1package

Примечания

  • The attack could not be reproduced on Linux. The upstream change from 1.0.32

  • only disables GLOB_BRACE, possibly to protect installations with a vulnerable libc

EPSS

Процентиль: 94%
0.07255
Низкий

Связанные уязвимости

ubuntu
около 15 лет назад

The glob implementation in Pure-FTPd before 1.0.32, and in libc in NetBSD 5.1, does not properly expand expressions containing curly brackets, which allows remote authenticated users to cause a denial of service (memory consumption) via a crafted FTP STAT command.

nvd
около 15 лет назад

The glob implementation in Pure-FTPd before 1.0.32, and in libc in NetBSD 5.1, does not properly expand expressions containing curly brackets, which allows remote authenticated users to cause a denial of service (memory consumption) via a crafted FTP STAT command.

github
около 4 лет назад

The glob implementation in Pure-FTPd before 1.0.32, and in libc in NetBSD 5.1, does not properly expand expressions containing curly brackets, which allows remote authenticated users to cause a denial of service (memory consumption) via a crafted FTP STAT command.

EPSS

Процентиль: 94%
0.07255
Низкий