VDB
CVE-2011-0762
CVE-2011-0762
PUBLISHED
CVSS 4 MEDIUM
The vsf_filename_passes_filter function in ls.c in vsftpd before 2.3.3 allows remote authenticated users to cause a denial of service (CPU consumption and process slot exhaustion) via crafted glob expressions in STAT commands in multiple FTP sessions, a different vulnerability than CVE-2010-2632.
EPSS 73.95% · 99.4th percentile
Risk Scores
CVSS 2.0
4
EPSS Score
73.95%
99.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| opensuse | opensuse | 11.2, 11.4, 11.3 |
| fedoraproject | fedora | 14, 15, 13 |
| suse | linux_enterprise_server | 10, 11, 9 |
| debian | debian_linux | 7.0, 5.0, 6.0 |
| canonical | ubuntu_linux | 8.04, 10.04, 9.10 |
| vsftpd_project | vsftpd | 0 |
| n/a | n/a | n/a |
Timeline
- Mar 2, 2011 CVE Published
- Mar 3, 2011 PoC Published
- Jan 5, 2022 PoC Published
- Feb 4, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
- May 29, 2023 PoC Published
- Jun 15, 2024 EPSS Score
- Jul 28, 2024 EPSS Score
- Sep 10, 2024 EPSS Score
- Dec 5, 2024 EPSS Score
- Jan 18, 2025 EPSS Score
- Feb 6, 2025 PoC Published
References
- Nuclei Template exploit
- FEDORA-2011-2590 vendor-advisory
- SUSE-SR:2011:009 vendor-advisory
- ADV-2011-0668 vdb
- 8109 third-party-advisory
- vsftpd-vsffilenamepassesfilter-dos(65873) vdb
- ftp://vsftpd.beasts.org/users/cevans/untar/vsftpd-2.3.4/Changelog url
- 1025186 vdb
- JVN#37417423 third-party-advisory
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=622741 url
- FEDORA-2011-2615 vendor-advisory
- ADV-2011-0547 vdb
- ADV-2011-0713 vdb
- RHSA-2011:0337 vendor-advisory
- http://www.exploit-db.com/exploits/16270 exploit
- http://www.kb.cert.org/vuls/id/590604 technical
- http://www.securityfocus.com/archive/1/516748/100/0/threaded advisory
- http://www.securityfocus.com/bid/46617 exploit
- http://marc.info/?l=bugtraq&m=133226187115472&w=2 issue
- http://www.ubuntu.com/usn/USN-1098-1 advisory
…and 7 more