First published: Fri Oct 09 2015(Updated: )
The glob implementation in tnftpd (formerly lukemftpd), as used in Apple OS X before 10.11, allows remote attackers to cause a denial of service (memory consumption and daemon outage) via a STAT command containing a crafted pattern, as demonstrated by multiple instances of the {..,..,..}/* substring.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Netbsd Tnftpd | ||
Apple Mac OS X | =10.10.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.