Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-30047

Опубликовано: 22 авг. 2023
Источник: redhat
CVSS3: 7.5

Описание

VSFTPD 3.0.3 allows attackers to cause a denial of service due to limited number of connections allowed.

VSFTPD is vulnerable to a denial of service, caused by only a limited number of connections allowed, a remote attacker could exploit this vulnerability to cause a denial of service condition.

Отчет

vsftpd has a configurable limit to the number of concurrent clients which can be accepted, max_clients. Obviously if this number is exceeded then service is denied to other clients. It is normal practice is to use e.g. firewall rules to limit denial of service attacks. As such, Red Hat does not consider this to be a real vulnerability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10vsftpdNot affected
Red Hat Enterprise Linux 6vsftpdOut of support scope
Red Hat Enterprise Linux 7vsftpdOut of support scope
Red Hat Enterprise Linux 8vsftpdNot affected
Red Hat Enterprise Linux 9vsftpdNot affected

Показывать по

Дополнительная информация

Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=2235683vsftpd: denial of service due to limited number of connections allowed

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 3 лет назад

VSFTPD 3.0.3 allows attackers to cause a denial of service due to limited number of connections allowed.

CVSS3: 7.5
nvd
около 3 лет назад

VSFTPD 3.0.3 allows attackers to cause a denial of service due to limited number of connections allowed.

CVSS3: 7.5
debian
около 3 лет назад

VSFTPD 3.0.3 allows attackers to cause a denial of service due to limi ...

CVSS3: 7.5
github
около 3 лет назад

VSFTPD 3.0.3 allows attackers to cause a denial of service due to limited number of connections allowed.

7.5 High

CVSS3