The vsf_filename_passes_filter function in ls.c in vsftpd before 2.3.3 allows remote authenticated users to cause a denial of service (CPU consumption and process slot exhaustion) via crafted glob expressions in STAT commands in multiple FTP sessions, a different vulnerability than CVE-2010-2632.
CVSS Details
- CVSS 3.1 Base Score: 6.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade vsftpd | Dec 1, 2016 | Mar 2, 2011 |
| Debian | — | Upgrade vsftpd | Jul 30, 2024 | Mar 2, 2011 |
| Gentoo Linux | — | Upgrade net-ftp/vsftpd. | Oct 30, 2017 | Mar 2, 2011 |
| Oracle_linux | — | Upgrade vsftpd | Oct 16, 2024 | Mar 2, 2011 |
| Suse | — | Upgrade vsftpdUpgrade sap-aio-release | Feb 17, 2015 | Mar 2, 2011 |
| Ubuntu | — | Upgrade vsftpd | Nov 8, 2024 | Mar 2, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub