CVE-2010-2632

Oracle Solaris 8-11 Express - DoS

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2010-2632. PoCs published by Maksymilian Arciemowicz.

AI-analyzed exploit summary This is a detailed writeup describing a resource exhaustion vulnerability in the glob(3) function across multiple vendors, leading to denial-of-service conditions in FTP servers and other applications. It includes technical analysis and proof-of-concept patterns but does not contain executable exploit code.

Description

Unspecified vulnerability in the FTP Server in Oracle Solaris 8, 9, 10, and 11 Express allows remote attackers to affect availability. NOTE: the previous information was obtained from the January 2011 CPU. Oracle has not commented on claims from a reliable researcher that this is an issue in the glob implementation in libc that allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames.

Exploits (1)

exploitdb WRITEUP
by Maksymilian Arciemowicz · textdosmultiple
https://www.exploit-db.com/exploits/15215

This is a detailed writeup describing a resource exhaustion vulnerability in the glob(3) function across multiple vendors, leading to denial-of-service conditions in FTP servers and other applications. It includes technical analysis and proof-of-concept patterns but does not contain executable exploit code.

Classification
Writeup 90%
Attack Type
Dos
Complexity
Moderate
Reliability
Reliable
Target: Multiple vendors' libc/glob(3) implementations (OpenBSD, NetBSD, FreeBSD, Solaris, glibc)
No auth needed
Prerequisites: Network access to vulnerable FTP server or application using glob(3) · Ability to send crafted glob patterns
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (11)

Core 11
Core References
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/55212
Third Party Advisory third-party-advisory x_refsource_sreasonres
http://securityreason.com/achievement_securityalert/89
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/43433
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/64798
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/42984
Vendor Advisory x_refsource_confirm
https://support.avaya.com/css/P8/documents/100127892
Third Party Advisory third-party-advisory x_refsource_sreasonres
http://securityreason.com/achievement_securityalert/97
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1024975
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2011/0151

Scores

EPSS 0.3236
EPSS Percentile 98.1%

Details

Status published
Products (4)
sun/sunos 5.8
sun/sunos 5.9
sun/sunos 5.10
sun/sunos 5.11
Published Jan 19, 2011
Tracked Since Feb 18, 2026