vsftpd FTP Server 'deny_file' Option Remote Denial of Service Vulnerability
BID:29322
Info
vsftpd FTP Server 'deny_file' Option Remote Denial of Service Vulnerability
| Bugtraq ID: | 29322 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2007-5962 |
| Remote: | Yes |
| Local: | No |
| Published: | May 21 2008 12:00AM |
| Updated: | Apr 13 2015 10:19PM |
| Credit: | Martin Nagy |
| Vulnerable: |
Vsftpd Vsftpd 2.0.5 rPath rPath Linux 2 Redhat Fedora 7 Redhat Enterprise Linux Desktop Workstation 5 client Redhat Enterprise Linux 5 Server |
| Not Vulnerable: | |
Discussion
vsftpd FTP Server 'deny_file' Option Remote Denial of Service Vulnerability
The 'vsftpd' FTP server is prone to a remote denial-of-service vulnerability because it fails to free allocated memory.
Successfully exploiting this issue allows remote attackers to crash the affected application, denying service to legitimate users.
The 'vsftpd' FTP server is prone to a remote denial-of-service vulnerability because it fails to free allocated memory.
Successfully exploiting this issue allows remote attackers to crash the affected application, denying service to legitimate users.
Exploit / POC
vsftpd FTP Server 'deny_file' Option Remote Denial of Service Vulnerability
Attackers can use readily available tools to exploit this issue.
The following proof-of-concept code is available:
Attackers can use readily available tools to exploit this issue.
The following proof-of-concept code is available:
Solution / Fix
vsftpd FTP Server 'deny_file' Option Remote Denial of Service Vulnerability
Solution:
Fixes are available. Please see the references for more information.
Solution:
Fixes are available. Please see the references for more information.
References
vsftpd FTP Server 'deny_file' Option Remote Denial of Service Vulnerability
References:
References: