REDHAT-BUG-704283: Medium severity Pure-FTPd Pure-FTPd vulnerability
Multiple libc/glob(3) flaws were reported [1] that affect various BSD libc implementations. In particular, globs containing braces could lead to resource exhaustion.
One such vulnerable application is Pure-FTPd. This has been corrected in upstream version 1.0.32, where support for braces expansion in directory listings was disabled.
[1] http://securityreason.com/achievementsecurityalert/97 [2] http://www.pureftpd.org/project/pure-ftpd/news
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-704283?
The severity of REDHAT-BUG-704283 is classified as a resource exhaustion vulnerability that can affect applications using the affected versions of libc/glob.
How do I fix REDHAT-BUG-704283?
To fix REDHAT-BUG-704283, update Pure-FTPd to version 1.0.32 or higher where the vulnerability has been addressed.
What are the main implications of REDHAT-BUG-704283?
The implications of REDHAT-BUG-704283 include potential denial of service through resource exhaustion when using brace expansion in glob patterns.
Which software is affected by REDHAT-BUG-704283?
Pure-FTPd versions before 1.0.32 are specifically affected by the vulnerabilities outlined in REDHAT-BUG-704283.
Is REDHAT-BUG-704283 related to any other vulnerabilities?
Yes, REDHAT-BUG-704283 is related to other similar flaws affecting various *BSD libc implementations and services that depend on the libc/glob functionality.