Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2011-0418

Опубликовано: 24 мая 2011
Источник: debian
EPSS Средний

Описание

The glob implementation in Pure-FTPd before 1.0.32, and in libc in NetBSD 5.1, does not properly expand expressions containing curly brackets, which allows remote authenticated users to cause a denial of service (memory consumption) via a crafted FTP STAT command.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
pure-ftpdfixed1.0.32-1package

Примечания

  • The attack could not be reproduced on Linux. The upstream change from 1.0.32

  • only disables GLOB_BRACE, possibly to protect installations with a vulnerable libc

EPSS

Процентиль: 94%
0.1463
Средний

Связанные уязвимости

ubuntu
больше 14 лет назад

The glob implementation in Pure-FTPd before 1.0.32, and in libc in NetBSD 5.1, does not properly expand expressions containing curly brackets, which allows remote authenticated users to cause a denial of service (memory consumption) via a crafted FTP STAT command.

nvd
больше 14 лет назад

The glob implementation in Pure-FTPd before 1.0.32, and in libc in NetBSD 5.1, does not properly expand expressions containing curly brackets, which allows remote authenticated users to cause a denial of service (memory consumption) via a crafted FTP STAT command.

github
больше 3 лет назад

The glob implementation in Pure-FTPd before 1.0.32, and in libc in NetBSD 5.1, does not properly expand expressions containing curly brackets, which allows remote authenticated users to cause a denial of service (memory consumption) via a crafted FTP STAT command.

EPSS

Процентиль: 94%
0.1463
Средний