CVE-2010-2072: Low severity pyftpdlib vulnerability
Published Jun 16, 2010
·Updated
Pyftpd 0.8.4 creates log files with predictable names in a temporary directory, which allows local users to cause a denial of service and obtain sensitive information.
Affected Software
1 affected component
Radovan Garabik Pyftpd=0.8.4
Event History
Jun 16, 2010
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2010-2072?
CVE-2010-2072 is considered a medium severity vulnerability due to its potential for denial of service and information disclosure.
2
How do I fix CVE-2010-2072?
To mitigate CVE-2010-2072, upgrade to a version of Pyftpd that addresses this vulnerability or implement access controls in the temporary directory.
3
What impacts does CVE-2010-2072 have on systems?
CVE-2010-2072 allows local users to disrupt service and access sensitive information by exploiting predictable log file names.
4
Which version of Pyftpd is affected by CVE-2010-2072?
CVE-2010-2072 specifically affects Pyftpd version 0.8.4.
5
Is CVE-2010-2072 exploitable remotely?
CVE-2010-2072 is not remotely exploitable as it requires local access to the system.