CVE-2005-0256: Buffer Overflow
Published Feb 25, 2005
·Updated
The wufnmatch function in wufnmatch.c in wu-ftpd 2.6.1 and 2.6.2 allows remote attackers to cause a denial of service (CPU exhaustion by recursion) via a glob pattern with a large number of (wildcard) characters, as demonstrated using the dir command.
Affected Software
2 affected components
Washington University Wu-ftpd=2.6.1
Washington University Wu-ftpd=2.6.2
Remediation
Patch Available
Event History
Feb 25, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-0256?
CVE-2005-0256 is considered a denial-of-service vulnerability that can cause CPU exhaustion.
2
How do I fix CVE-2005-0256?
To mitigate CVE-2005-0256, upgrade from wu-ftpd versions 2.6.1 or 2.6.2 to a patched version.
3
Which versions of wu-ftpd are affected by CVE-2005-0256?
CVE-2005-0256 affects wu-ftpd version 2.6.1 and 2.6.2.
4
Can CVE-2005-0256 be exploited remotely?
Yes, CVE-2005-0256 can be exploited remotely through crafted glob patterns.
5
What impact does CVE-2005-0256 have on the system?
CVE-2005-0256 can lead to a denial of service by exhausting CPU resources, potentially affecting system availability.