20010817 [ASGUARD-LABS] glFTPD v1.23 DOS Attackmailing list
http://archives.neohapsis.com/archives/bugtraq/2001-08/0239.html CVE-2001-0965
glFTPd 1.x - 'LIST' Denial of Service
Record summary
CVE-2001-0965 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit.
Description
glFTPD 1.23 allows remote attackers to cause a denial of service (CPU consumption) via a LIST command with an argument that contains a large number of * (asterisk) characters.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBglFTPd 1.x - 'LIST' Denial of ServiceExploitDB exploitby ASGUARD LABSNot analyzed1 file
References
5glftpd.orgConfirmation
http://www.glftpd.org/ glftpd-list-dos(7001)vdb entry
http://www.iss.net/security_center/static/7001.php 3201vdb entry
http://www.securityfocus.com/bid/3201 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2001-0965