The vsf_filename_passes_filter function in ls.c in vsftpd before 2.3.3 allows remote authenticated users to cause a denial of service (CPU consumption and process slot exhaustion) via crafted glob expressions in STAT commands in multiple FTP sessions, a different vulnerability than CVE-2010-2632.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-400,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| canonical | ubuntu_linux | 8.04 |
| canonical | ubuntu_linux | 10.04 |
| canonical | ubuntu_linux | 9.10 |
| suse | linux_enterprise_server | 9 |
| fedoraproject | fedora | 14 |
| opensuse | opensuse | 11.2 |
| vsftpd_project | vsftpd | * |
| suse | linux_enterprise_server | 10 |
| debian | debian_linux | 6.0 |
| debian | debian_linux | 7.0 |
| canonical | ubuntu_linux | 10.10 |
| canonical | ubuntu_linux | 6.06 |
| fedoraproject | fedora | 15 |
| debian | debian_linux | 5.0 |
| opensuse | opensuse | 11.3 |
| opensuse | opensuse | 11.4 |
| fedoraproject | fedora | 13 |
| suse | linux_enterprise_server | 11 |
Unspecified vulnerability in vsftpd 3.0.2 and earlier allows remote attackers to bypass access restrictions via unknown vectors, related to deny_file parsing.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| opensuse | opensuse | 13.1 |
| vsftpd_project | vsftpd | * |
| opensuse | opensuse | 13.2 |