5
CVSSv2

CVE-2001-0965

Published: 31/08/2001 Updated: 05/09/2008
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

glFTPD 1.23 allows remote malicious users to cause a denial of service (CPU consumption) via a LIST command with an argument that contains a large number of * (asterisk) characters.

Vulnerable Product Search on Vulmon Subscribe to Product

glftpd glftpd 1.16.9

glftpd glftpd 1.18a

glftpd glftpd 1.23

glftpd glftpd 1.19

glftpd glftpd 1.20

glftpd glftpd 1.21

glftpd glftpd 1.22b

glftpd glftpd 1.13.6

glftpd glftpd 1.17.2

Exploits

source: wwwsecurityfocuscom/bid/3201/info glFtpD contains an input validation error that may allow a malicious user to cause a denial of service against a host running the daemon The problem occurs when a specially crafted 'LIST' command is received by the server If the argument to the command contains an excessive number of '*' charac ...