Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2001-0965

Overview

Vulnerability Score 5.0 5.0
CVE Id CVE-2001-0965
Last Modified 05 Sep 2008 04:25:21
Published 31 Aug 2001 12:00:00
Confidentiality Impact NONE NONE
Integrity Impact NONE NONE
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2001-0965

Summary

glFTPD 1.23 allows remote attackers to cause a denial of service (CPU consumption) via a LIST command with an argument that contains a large number of * (asterisk) characters.

Vulnerable Systems

Application

  • Glftpd 1.13.6

  • Glftpd 1.16.9

  • Glftpd 1.17.2

  • Glftpd 1.18a

  • Glftpd 1.19

  • Glftpd 1.20

  • Glftpd 1.21

  • Glftpd 1.22b

  • Glftpd 1.23


References

BID - 3201

BUGTRAQ - 20010817 [ASGUARD-LABS] glFTPD v1.23 DOS Attack

CONFIRM - http://www.glftpd.org/

XF - glftpd-list-dos(7001)


Last Updated: 27 May 2016 10:36:28