CVE-2009-5013: Medium severity pyftpdlib vulnerability
Published Oct 19, 2010
·Updated
Memory leak in the ondtpclose function in ftpserver.py in pyftpdlib before 0.5.2 allows remote authenticated users to cause a denial of service (memory consumption) by sending a QUIT command during a data transfer.
Affected Software
8 affected componentsFixes available
pip/pyftpdlib<=0.5.1
0.5.2
G.rodola Pyftpdlib<=0.5.1
G.rodola Pyftpdlib=0.1
G.rodola Pyftpdlib=0.1.1
G.rodola Pyftpdlib=0.2.0
G.rodola Pyftpdlib=0.3.0
G.rodola Pyftpdlib=0.4.0
G.rodola Pyftpdlib=0.5.0
Event History
Oct 19, 2010
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Data Sourced
via NVD·08:00 PM
DescriptionSeverityWeaknessAffected Software
May 2, 2022
Advisory Published
via GitHub·04:00 AM
Frequently Asked Questions
1
What is the severity of CVE-2009-5013?
CVE-2009-5013 has a medium severity level due to its potential to cause denial of service by exhausting memory resources.
2
How do I fix CVE-2009-5013?
To fix CVE-2009-5013, upgrade pyftpdlib to version 0.5.2 or later.
3
What is the impact of CVE-2009-5013 on my system?
The impact of CVE-2009-5013 is that remote authenticated users can cause a denial of service by triggering a memory leak.
4
Which versions of pyftpdlib are affected by CVE-2009-5013?
CVE-2009-5013 affects all versions of pyftpdlib prior to 0.5.2.
5
Can CVE-2009-5013 be exploited remotely?
Yes, CVE-2009-5013 can be exploited by remote authenticated users sending a QUIT command during a data transfer.