Vulnerability Name: | CVE-2005-0256 (CCN-19495) | ||||||||||||||||||||
Assigned: | 2005-02-25 | ||||||||||||||||||||
Published: | 2005-02-25 | ||||||||||||||||||||
Updated: | 2017-10-11 | ||||||||||||||||||||
Summary: | The wu_fnmatch function in wu_fnmatch.c in wu-ftpd 2.6.1 and 2.6.2 allows remote attackers to cause a denial of service (CPU exhaustion by recursion) via a glob pattern with a large number of * (wildcard) characters, as demonstrated using the dir command. | ||||||||||||||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
| ||||||||||||||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
| ||||||||||||||||||||
Vulnerability Type: | CWE-119 | ||||||||||||||||||||
Vulnerability Consequences: | Denial of Service | ||||||||||||||||||||
References: | Source: SCO Type: UNKNOWN SCOSA-2005.63 Source: MITRE Type: CNA CVE-2005-0256 Source: HP Type: UNKNOWN SSRT061110 Source: CCN Type: SA14411 WU-FTPD Wildcard Denial of Service Vulnerability Source: SECUNIA Type: Vendor Advisory 14411 Source: SECUNIA Type: Vendor Advisory 18210 Source: SECUNIA Type: Vendor Advisory 19561 Source: SUNALERT Type: UNKNOWN 101699 Source: SUNALERT Type: UNKNOWN 57795 Source: CCN Type: ASA-2006-091 HP-UX wu-ftpd Remote Denial of Service (HPSBUX02110) Source: DEBIAN Type: Patch, Vendor Advisory DSA-705 Source: DEBIAN Type: DSA-705 wu-ftpd -- missing input sanitising Source: IDEFENSE Type: Exploit 20050225 WU-FTPD File Globbing Denial of Service Vulnerability Source: CCN Type: iDEFENSE Security Advisory 02.25.05 WU-FTPD File Globbing Denial of Service Vulnerability Source: OSVDB Type: UNKNOWN 14203 Source: CCN Type: OSVDB ID: 14203 WU-FTPD wu_fnmatch() Function File Globbing Remote DoS Source: VUPEN Type: Vendor Advisory ADV-2005-0588 Source: VUPEN Type: Vendor Advisory ADV-2006-1271 Source: CCN Type: WU-FTPD Web site WU-FTPD Development Group Source: XF Type: UNKNOWN wuftpd-wufnmatch-asterisk-dos(19495) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:1265 Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:1333 Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:1762 | ||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||
| |||||||||||||||||||||
BACK |