CVE-2011-0762: Medium severity vsftpd vulnerability
The vsffilenamepassesfilter function in ls.c in vsftpd before 2.3.3 allows remote authenticated users to cause a denial of service (CPU consumption and process slot exhaustion) via crafted glob expressions in STAT commands in multiple FTP sessions, a different vulnerability than CVE-2010-2632.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-0762?
CVE-2011-0762 is classified as a denial of service vulnerability affecting multiple versions of vsftpd.
How do I fix CVE-2011-0762?
To mitigate CVE-2011-0762, upgrade vsftpd to version 2.3.3 or later.
What software is affected by CVE-2011-0762?
CVE-2011-0762 affects vsftpd versions prior to 2.3.3 and various Linux distributions including certain versions of Ubuntu, Fedora, Debian, and SUSE.
What type of attack does CVE-2011-0762 enable?
CVE-2011-0762 allows remote authenticated users to create CPU consumption and process slot exhaustion through crafted glob expressions.
Is there a workaround for CVE-2011-0762?
A temporary workaround for CVE-2011-0762 is to limit the number of allowed FTP sessions per user.