VDB
CVE-2011-0762
CVE-2011-0762
PUBLISHED
CVSS 4 MEDIUM
The vsf_filename_passes_filter function in ls.c in vsftpd before 2.3.3 allows remote authenticated users to cause a denial of service (CPU consumption and process slot exhaustion) via crafted glob expressions in STAT commands in multiple FTP sessions, a different vulnerability than CVE-2010-2632.
EPSS 16.70% · 95.1th percentile
Risk Scores
CVSS 2.0
4
EPSS Score
16.70%
95.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| opensuse | opensuse | 11.2, 11.4, 11.3 |
| fedoraproject | fedora | 14, 15, 13 |
| suse | linux_enterprise_server | 10, 11, 9 |
| debian | debian_linux | 7.0, 5.0, 6.0 |
| canonical | ubuntu_linux | 8.04, 10.04, 9.10 |
| vsftpd_project | vsftpd | 0 |
| n/a | n/a | n/a |
Timeline
- Mar 2, 2011 CVE Published
- Mar 3, 2011 PoC Published
- Jan 5, 2022 PoC Published
- Feb 4, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
- May 29, 2023 PoC Published
- Jun 15, 2024 EPSS Score
- Jul 28, 2024 EPSS Score
- Aug 6, 2024 CVE Updated
- Sep 10, 2024 EPSS Score
- Dec 5, 2024 EPSS Score
- Jan 18, 2025 EPSS Score
References
- FEDORA-2011-2590 vendor-advisory
- HPSBMU02752 vendor-advisory
- SUSE-SR:2011:009 vendor-advisory
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=622741 url
- FEDORA-2011-2615 vendor-advisory
- ADV-2011-0639 vdb
- ADV-2011-0668 vdb
- DSA-2305 vendor-advisory
- 20110301 vsftpd 2.3.2 remote denial-of-service mailing-list
- 8109 third-party-advisory
- ADV-2011-0547 vdb
- 16270 exploit
- vsftpd-vsffilenamepassesfilter-dos(65873) vdb
- http://cxib.net/stuff/vspoc232.c url
- MDVSA-2011:049 vendor-advisory
- ftp://vsftpd.beasts.org/users/cevans/untar/vsftpd-2.3.4/Changelog url
- ADV-2011-0713 vdb
- FEDORA-2011-2567 vendor-advisory
- USN-1098-1 vendor-advisory
- VU#590604 third-party-advisory
…and 6 more