CVE-2011-0418 PUBLISHED CVSS 4 MEDIUM

The glob implementation in Pure-FTPd before 1.0.32, and in libc in NetBSD 5.1, does not properly expand expressions containing curly brackets, which allows remote authenticated users to cause a denial of service (memory consumption) via a crafted FTP STAT command.

EPSS 13.78% · 94.2th percentile

Risk Scores

CVSS v2.0
4
EPSS Score
13.78%
94.2th percentile

Affected Products

VendorProductVersions
netbsdnetbsd5.1
pureftpdpure-ftpd0, 0.90, 0.91
n/an/an/a

Timeline

References

Open in Interactive Console →