Описание
VSFTPD 3.0.3 allows attackers to cause a denial of service due to limited number of connections allowed.
VSFTPD is vulnerable to a denial of service, caused by only a limited number of connections allowed, a remote attacker could exploit this vulnerability to cause a denial of service condition.
Отчет
vsftpd has a configurable limit to the number of concurrent clients which can be accepted, max_clients. Obviously if this number is exceeded then service is denied to other clients. It is normal practice is to use e.g. firewall rules to limit denial of service attacks. As such, Red Hat does not consider this to be a real vulnerability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | vsftpd | Not affected | ||
| Red Hat Enterprise Linux 6 | vsftpd | Out of support scope | ||
| Red Hat Enterprise Linux 7 | vsftpd | Out of support scope | ||
| Red Hat Enterprise Linux 8 | vsftpd | Not affected | ||
| Red Hat Enterprise Linux 9 | vsftpd | Not affected |
Показывать по
Дополнительная информация
7.5 High
CVSS3
Связанные уязвимости
VSFTPD 3.0.3 allows attackers to cause a denial of service due to limited number of connections allowed.
VSFTPD 3.0.3 allows attackers to cause a denial of service due to limited number of connections allowed.
VSFTPD 3.0.3 allows attackers to cause a denial of service due to limi ...
VSFTPD 3.0.3 allows attackers to cause a denial of service due to limited number of connections allowed.
7.5 High
CVSS3