WU-FTPD wu_fnmatch() Function File Globbing Remote DoS

high Nessus Plugin ID 17602

Synopsis

The remote FTP server has a denial of service vulnerability.

Description

The version of WU-FTPD running on the remote host exhausts all available resources on the server when it repeatedly receives the following command :

LIST *****[...]*.*

This issue has been confirmed in WU-FTPD 2.6.2 and earlier.

Solution

Apply the latest vendor patches.

See Also

http://www.nessus.org/u?bad5e32a

Plugin Details

Severity: High

ID: 17602

File Name: wu_ftpd_glob2.nasl

Version: 1.20

Type: remote

Family: FTP

Published: 3/23/2005

Updated: 8/5/2020

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.4

CVSS v2

Risk Factor: High

Base Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Information

Vulnerability Publication Date: 2/25/2005

Reference Information

CVE: CVE-2005-0256

CWE: 119