| » Topic: | vsftpd flaw could disable wide range of servers |
» Added by: SecurityReason
» Date: 01.03.2011
New advisory about vulnerability in vsftpd server "vsftpd 2.3.2 remote denial-of-service". A 'resource exhaustion' vulnerability has been identified in ls.c file.
The potential scale of risk is high.
Examples of vulnerable servers:
- ftp.gnu.org
- ftp.kernel.org
- ftpgen.wip4.adobe.com
- ftp.oracle.com
- ftp.freebsd.org
Any code with huge complexity, could allow of denial of service if an affected system received vulnerable pattern.
More:
http://securityreason.com/achievement_securityalert/95
Exploit:
http://cxib.net/stuff/vspoc232.c
Fix for this issue has been created together with vsftpd projects.
ChangeLog:
ftp://vsftpd.beasts.org/users/cevans/untar/vsftpd-2.3.4/Changelog
|