Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-14242

Опубликовано: 14 янв. 2026
Источник: debian
EPSS Низкий

Описание

A flaw was found in vsftpd. This vulnerability allows a denial of service (DoS) via an integer overflow in the ls command parameter parsing, triggered by a remote, authenticated attacker sending a crafted STAT command with a specific byte sequence.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
vsftpdnot-affectedpackage

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=2419826

  • RedHat specific patch fix: https://src.fedoraproject.org/rpms/vsftpd/c/2ed5ba6e77f1c3e365fb4b0028945f762c456131

EPSS

Процентиль: 35%
0.00143
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
3 месяца назад

A flaw was found in vsftpd. This vulnerability allows a denial of service (DoS) via an integer overflow in the ls command parameter parsing, triggered by a remote, authenticated attacker sending a crafted STAT command with a specific byte sequence.

CVSS3: 6.5
redhat
3 месяца назад

A flaw was found in vsftpd. This vulnerability allows a denial of service (DoS) via an integer overflow in the ls command parameter parsing, triggered by a remote, authenticated attacker sending a crafted STAT command with a specific byte sequence.

CVSS3: 6.5
nvd
3 месяца назад

A flaw was found in vsftpd. This vulnerability allows a denial of service (DoS) via an integer overflow in the ls command parameter parsing, triggered by a remote, authenticated attacker sending a crafted STAT command with a specific byte sequence.

rocky
3 месяца назад

Moderate: vsftpd security update

rocky
3 месяца назад

Moderate: vsftpd security update

EPSS

Процентиль: 35%
0.00143
Низкий