4
CVSSv2

CVE-2010-4754

Published: 02/03/2011 Updated: 21/09/2011
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P

Vulnerability Summary

The glob implementation in libc in FreeBSD 7.3 and 8.1, NetBSD 5.0.2, and OpenBSD 4.7, and Libsystem in Apple Mac OS X prior to 10.6.8, allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632.

Vulnerable Product Search on Vulmon Subscribe to Product

freebsd freebsd 7.3

freebsd freebsd 8.1

openbsd openbsd 4.7

netbsd netbsd 5.0.2

apple mac os x

Exploits

Multiple vendors are affected by a memory exhaustion vulnerability in libc/glob(3) GLOB_BRACE|GLOB_LIMIT ...