MidnightBSD

Advisories for vsftpd_project

CVE-2011-0762 MEDIUM

The vsf_filename_passes_filter function in ls.c in vsftpd before 2.3.3 allows remote authenticated users to cause a denial of service (CPU consumption and process slot exhaustion) via crafted glob expressions in STAT commands in multiple FTP sessions, a different vulnerability than CVE-2010-2632.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-400,

Products Affected

Vendor Product Version
canonical ubuntu_linux 8.04
canonical ubuntu_linux 10.04
canonical ubuntu_linux 9.10
suse linux_enterprise_server 9
fedoraproject fedora 14
opensuse opensuse 11.2
vsftpd_project vsftpd *
suse linux_enterprise_server 10
debian debian_linux 6.0
debian debian_linux 7.0
canonical ubuntu_linux 10.10
canonical ubuntu_linux 6.06
fedoraproject fedora 15
debian debian_linux 5.0
opensuse opensuse 11.3
opensuse opensuse 11.4
fedoraproject fedora 13
suse linux_enterprise_server 11
CVE-2015-1419 MEDIUM

Unspecified vulnerability in vsftpd 3.0.2 and earlier allows remote attackers to bypass access restrictions via unknown vectors, related to deny_file parsing.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
opensuse opensuse 13.1
vsftpd_project vsftpd *
opensuse opensuse 13.2