CVE-2011-0762

NUCLEI

Vsftpd < 2.3.3 - Denial of Service

Title source: rule

Description

The vsf_filename_passes_filter function in ls.c in vsftpd before 2.3.3 allows remote authenticated users to cause a denial of service (CPU consumption and process slot exhaustion) via crafted glob expressions in STAT commands in multiple FTP sessions, a different vulnerability than CVE-2010-2632.

Exploits (3)

exploitdb WORKING POC VERIFIED
by Maksymilian Arciemowicz · cdoslinux
https://www.exploit-db.com/exploits/16270
nomisec WORKING POC
by s3mPr1linux · poc
https://github.com/s3mPr1linux/CVE-2011-0762
metasploit WORKING POC
rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/dos/ftp/vsftpd_232.rb

Nuclei Templates (1)

vsftpd < 2.3.3 - DoS
MEDIUMVERIFIEDby pussycat0x
Shodan: vsftpd || product:"vsftpd"

References (25)

... and 5 more

Scores

EPSS 0.4528
EPSS Percentile 97.6%

Details

CWE
CWE-400
Status published
Products (18)
canonical/ubuntu_linux 6.06
canonical/ubuntu_linux 8.04
canonical/ubuntu_linux 9.10
canonical/ubuntu_linux 10.04
canonical/ubuntu_linux 10.10
debian/debian_linux 5.0
debian/debian_linux 6.0
debian/debian_linux 7.0
fedoraproject/fedora 13
fedoraproject/fedora 14
... and 8 more
Published Mar 02, 2011
Tracked Since Feb 18, 2026