CVE-2008-2375: High severity red hat enterprise linux vulnerability
Memory leak in a certain Red Hat deployment of vsftpd before 2.0.5 on Red Hat Enterprise Linux (RHEL) 3 and 4, when PAM is used, allows remote attackers to cause a denial of service (memory consumption) via a large number of invalid authentication attempts within the same session, a different vulnerability than CVE-2007-5962.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-2375?
CVE-2008-2375 is classified as a denial of service vulnerability due to memory leak which can be exploited by remote attackers.
How do I fix CVE-2008-2375?
To fix CVE-2008-2375, upgrade to vsftpd version 2.0.5 or later, or apply the relevant patches from Red Hat.
Which versions are affected by CVE-2008-2375?
CVE-2008-2375 affects several versions of vsftpd prior to 2.0.5 on Red Hat Enterprise Linux 3 and 4.
Can CVE-2008-2375 be exploited remotely?
Yes, CVE-2008-2375 can be exploited remotely through numerous invalid authentication attempts within the same session.
What product is primarily affected by CVE-2008-2375?
CVE-2008-2375 primarily affects the vsftpd software implementation in specific Red Hat Enterprise Linux environments.