CVE-2011-0418
Severity CVSS v4.0:
Pending analysis
Type:
CWE-20
Input Validation
Publication date:
24/05/2011
Last modified:
11/04/2025
Description
The glob implementation in Pure-FTPd before 1.0.32, and in libc in NetBSD 5.1, does not properly expand expressions containing curly brackets, which allows remote authenticated users to cause a denial of service (memory consumption) via a crafted FTP STAT command.
Impact
Base Score 2.0
4.00
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:pureftpd:pure-ftpd:*:*:*:*:*:*:*:* | 1.0.31 (including) | |
cpe:2.3:a:pureftpd:pure-ftpd:0.90:*:*:*:*:*:*:* | ||
cpe:2.3:a:pureftpd:pure-ftpd:0.91:*:*:*:*:*:*:* | ||
cpe:2.3:a:pureftpd:pure-ftpd:0.92:*:*:*:*:*:*:* | ||
cpe:2.3:a:pureftpd:pure-ftpd:0.93:*:*:*:*:*:*:* | ||
cpe:2.3:a:pureftpd:pure-ftpd:0.94:*:*:*:*:*:*:* | ||
cpe:2.3:a:pureftpd:pure-ftpd:0.95:*:*:*:*:*:*:* | ||
cpe:2.3:a:pureftpd:pure-ftpd:0.95-pre1:*:*:*:*:*:*:* | ||
cpe:2.3:a:pureftpd:pure-ftpd:0.95-pre2:*:*:*:*:*:*:* | ||
cpe:2.3:a:pureftpd:pure-ftpd:0.95-pre3:*:*:*:*:*:*:* | ||
cpe:2.3:a:pureftpd:pure-ftpd:0.95-pre4:*:*:*:*:*:*:* | ||
cpe:2.3:a:pureftpd:pure-ftpd:0.95.1:*:*:*:*:*:*:* | ||
cpe:2.3:a:pureftpd:pure-ftpd:0.95.2:*:*:*:*:*:*:* | ||
cpe:2.3:a:pureftpd:pure-ftpd:0.96:*:*:*:*:*:*:* | ||
cpe:2.3:a:pureftpd:pure-ftpd:0.96.1:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://cvsweb.netbsd.org/bsdweb.cgi/src/lib/libc/gen/glob.c#rev1.28
- http://cvsweb.netbsd.org/bsdweb.cgi/src/lib/libc/gen/glob.c.diff?r1=1.27&r2=1.28&f=h
- http://securityreason.com/achievement_securityalert/97
- http://securityreason.com/securityalert/8228
- http://www.mandriva.com/security/advisories?name=MDVSA-2011%3A094
- http://www.pureftpd.org/project/pure-ftpd/news
- http://www.securityfocus.com/bid/47671
- http://www.vupen.com/english/advisories/2011/1273
- https://bugzilla.redhat.com/show_bug.cgi?id=704283
- http://cvsweb.netbsd.org/bsdweb.cgi/src/lib/libc/gen/glob.c#rev1.28
- http://cvsweb.netbsd.org/bsdweb.cgi/src/lib/libc/gen/glob.c.diff?r1=1.27&r2=1.28&f=h
- http://securityreason.com/achievement_securityalert/97
- http://securityreason.com/securityalert/8228
- http://www.mandriva.com/security/advisories?name=MDVSA-2011%3A094
- http://www.pureftpd.org/project/pure-ftpd/news
- http://www.securityfocus.com/bid/47671
- http://www.vupen.com/english/advisories/2011/1273
- https://bugzilla.redhat.com/show_bug.cgi?id=704283