First published: Wed Jun 16 2010(Updated: )
Pyftpd 0.8.4 creates log files with predictable names in a temporary directory, which allows local users to cause a denial of service and obtain sensitive information.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Pyftpdlib | =0.8.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-2072 is considered a medium severity vulnerability due to its potential for denial of service and information disclosure.
To mitigate CVE-2010-2072, upgrade to a version of Pyftpd that addresses this vulnerability or implement access controls in the temporary directory.
CVE-2010-2072 allows local users to disrupt service and access sensitive information by exploiting predictable log file names.
CVE-2010-2072 specifically affects Pyftpd version 0.8.4.
CVE-2010-2072 is not remotely exploitable as it requires local access to the system.