Where
-Infinity
0
Severity
2.3
AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N/E:X/RL:X/RC:R

A vulnerability was identified in D-Link DIR-842 2.01.B04. This impacts an unknown function of the file /etc/vsftpd.conf of the component vsftpd. Such manipulation leads to incorrect default permissions. It is possible to launch the attack remotely. A high complexity level is associated with this attack. The exploitability is said to be difficult.

First published (updated )
Severity
2.1
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R

A vulnerability was determined in TOTOLINK CP450 4.1.0cu.747. This vulnerability affects unknown code of the file /etc/vsftpd.conf of the component vsftpd. This manipulation causes least privilege violation. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized.

First published (updated )
Severity
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

An issue in H3C M102G HM1A0V200R010 wireless controller and BA1500L SWBA1A0V100R006 wireless access point, there is a misconfiguration vulnerability about vsftpd. Through this vulnerability, all files uploaded anonymously via the FTP protocol is automatically owned by the root user and remote attackers could gain root-level control over the devices.

First published (updated )
Severity
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

VSFTPD 3.0.3 allows attackers to cause a denial of service due to limited number of connections allowed.

First published (updated )
Severity
4
AV:N/AC:L/Au:S/C:N/I:N/A:P

The vsffilenamepassesfilter function in ls.c in vsftpd before 2.3.3 allows remote authenticated users to cause a denial of service (CPU consumption and process slot exhaustion) via crafted glob expressions in STAT commands in multiple FTP sessions, a different vulnerability than CVE-2010-2632.

First published (updated )
Severity
5
AV:N/AC:L/Au:N/C:N/I:P/A:N

Unspecified vulnerability in vsftpd 3.0.2 and earlier allows remote attackers to bypass access restrictions via unknown vectors, related to denyfile parsing.

First published (updated )
Severity
4

Vadim Ponomarev (ccrssaa at karelia.ru), report a pid namespace leak caused by vsftpd.

Detailed discussion can be found in: https://bugzilla.novell.com/showbug.cgi?id=757783

Introduced by: http://git.kernel.org/linus/423e0ab086ad8b33626e45fa94ac7613146b7ffa

Upstream commit: http://git.kernel.org/linus/905ad269c55fc62bee3da29f7b1d1efeba8aa1e1

Steps to reproduce: https://bugzilla.novell.com/showbug.cgi?id=757783#c0

Acknowledgements:

Red Hat would like to thank Vadim Ponomarev for reporting this issue.

First published (updated )
Severity
1
Infoleak

/proc/PID/io may be used for gathering private information. E.g. for openssh and vsftpd daemons wchars/rchars may be used to learn the precise password length.

[0/2] restrict statistics information to user https://lkml.org/lkml/2011/6/24/88 [1/2] proc: restrict access to /proc/PID/io (CVE-2011-2495) https://patchwork.kernel.org/patch/916032/ [2/2] taskstats: restrict access to user (CVE-2011-2494) https://patchwork.kernel.org/patch/916042/

taskstats authorizedkeys presence infoleak PoC http://seclists.org/oss-sec/2011/q2/659

Acknowledgements:

Red Hat would like to thank Vasiliy Kulikov of Openwall for reporting this issue.

First published (updated )
Severity
1
Infoleak

taskstats information may be used for gathering private information. E.g. for openssh and vsftpd daemons readcharacters/writecharacters may be used to learn the precise password length. Restrict it to processes being able to ptrace the target process. For TASKSTATSCMDATTRREGISTERCPUMASK the fix is euid check instead of a ptrace check as the handler is processed in the context of the target process, not the listener process'. When ptracetaskmayaccesscurrent() is introduced, it should be used instead of euid check. Currently there is a small race when a process temporarily changes its euid (e.g. to access user's files), until the process sets euid back user's processes may gather privileged process' statistics.

taskstats authorizedkeys presence infoleak PoC http://seclists.org/oss-sec/2011/q2/659

[0/2] restrict statistics information to user https://lkml.org/lkml/2011/6/24/88 [1/2] proc: restrict access to /proc/PID/io (CVE-2011-2495) https://patchwork.kernel.org/patch/916032/ [2/2] taskstats: restrict access to user (CVE-2011-2494) https://patchwork.kernel.org/patch/916042/

http://article.gmane.org/gmane.comp.security.oss.general/5337 Linus suggested returning accounting information at a 1k granularity instead.

Acknowledgements:

Red Hat would like to thank Vasiliy Kulikov of Openwall for reporting this issue.

First published (updated )
Severity
4
Buffer Overflow, Integer Overflow

There exists a integer overflow to buffer overflow vulnerability within tzfileread function of the GNU C Library. This vulnerability was published by dividead early in 2009 in the following blog post:

http://dividead.wordpress.com/2009/06/01/glibc-timezone-integer-overflow/

In December 3, Kingcope, at Full Disclosure Mailing List, noted vsftpd as one possible attack vector for this issue:

http://lists.grok.org.uk/pipermail/full-disclosure/2011-December/084452.html

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203