VDB
CVE-2007-5962
CVE-2007-5962
PUBLISHED
CVSS 7.099999904632568 HIGH
Memory leak in a certain Red Hat patch, applied to vsftpd 2.0.5 on Red Hat Enterprise Linux (RHEL) 5 and Fedora 6 through 8, and on Foresight Linux and rPath appliances, allows remote attackers to cause a denial of service (memory consumption) via a large number of CWD commands, as demonstrated by an attack on a daemon with the deny_file configuration option.
EPSS 12.06% · 95.7th percentile
Risk Scores
CVSS 2.0
7.099999904632568
EPSS Score
12.06%
95.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| rpath | appliance_platform_agent | |
| redhat | fedora | 6, 7, 8 |
| redhat | enterprise_linux | 5.0 |
| n/a | n/a | n/a |
| foresight_linux | appliances |
Timeline
- May 21, 2008 PoC Published
- May 22, 2008 CVE Published
- Jun 14, 2008 PoC Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 26, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
References
- FEDORA-2008-4347 vendor-advisory
- RHSA-2008:0295 vendor-advisory
- [oss-security] 20080521 Re: vsftpd CVE-2007-5962 (Red Hat / Fedora specific) mailing-list
- https://bugzilla.redhat.com/show_bug.cgi?id=397011 url
- FEDORA-2008-4373 vendor-advisory
- [oss-security] 20080521 vsftpd CVE-2007-5962 (Red Hat / Fedora specific) mailing-list
- http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0185 url
- 30341 third-party-advisory
- 5814 exploit
- 30354 third-party-advisory
- FEDORA-2008-4362 vendor-advisory
- vsftpd-denyfile-dos(42593) vdb
- ADV-2008-1600 vdb
- [oss-security] 20080521 Re: vsftpd CVE-2007-5962 (Red Hat / Fedora specific) mailing-list
- 29322 vdb
- oval:org.mitre.oval:def:8850 vdb
- 20080606 rPSA-2008-0185-1 vsftpd mailing-list
- 1020079 vdb
- https://nvd.nist.gov/vuln/detail/CVE-2007-5962 advisory
- https://access.redhat.com/errata/RHSA-2008:0295 url
…and 1 more