CVE-2005-0256

Washington University Wu-ftpd - Memory Corruption

Title source: rule

Description

The wu_fnmatch function in wu_fnmatch.c in wu-ftpd 2.6.1 and 2.6.2 allows remote attackers to cause a denial of service (CPU exhaustion by recursion) via a glob pattern with a large number of * (wildcard) characters, as demonstrated using the dir command.

Exploits (1)

exploitdb WORKING POC VERIFIED
by str0ke · cdoslinux
https://www.exploit-db.com/exploits/842

Scores

EPSS 0.2655
EPSS Percentile 96.3%

Details

CWE
CWE-119
Status published
Products (2)
washington_university/wu-ftpd 2.6.1
washington_university/wu-ftpd 2.6.2
Published May 02, 2005
Tracked Since Feb 18, 2026