Vulnerabilities > CVE-2001-1501 - Unspecified vulnerability in Proftpd Project Proftpd 1.2.1
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
The glob functionality in ProFTPD 1.2.1, and possibly other versions allows remote attackers to cause a denial of service (CPU and memory consumption) via commands with large numbers of wildcard and other special characters, as demonstrated using an ls command with multiple (1) "*/..", (2) "*/.*", or (3) ".*./*?/" sequences in the argument.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | wu-ftpd 2.4/2.5/2.6,Trolltech ftpd 1.2,ProFTPD 1.2,BeroFTPD 1.3.4 FTP glob Expansion Vulnerability. CVE-2001-1501. Remote exploit for linux platform |
id | EDB-ID:20690 |
last seen | 2016-02-02 |
modified | 2001-03-15 |
published | 2001-03-15 |
reporter | Frank DENIS |
source | https://www.exploit-db.com/download/20690/ |
title | wu-ftpd 2.4/2.5/2.6,Trolltech ftpd 1.2,ProFTPD 1.2,BeroFTPD 1.3.4 FTP - glob Expansion Vulnerability |
Nessus
NASL family | Mandriva Local Security Checks |
NASL id | MANDRAKE_MDKSA-2002-005.NASL |
description | Matthew S. Hallacy discovered that ProFTPD was not forward resolving reverse-resolved hostnames. A remote attacker could exploit this to bypass ProFTPD access controls or have false information logged. Frank Denis discovered that a remote attacker could send malicious commands to the ProFTPD server and it would force the process to consume all CPU and memory resources available to it. This DoS vulnerability could bring the server down with repeated attacks. Finally, Mattias found a segmentation fault problem that is considered by the developers to be unexploitable. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 13913 |
published | 2004-07-31 |
reporter | This script is Copyright (C) 2004-2019 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/13913 |
title | Mandrake Linux Security Advisory : proftpd (MDKSA-2002:005) |
code |
|
References
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000450
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000450
- http://online.securityfocus.com/archive/1/169395
- http://online.securityfocus.com/archive/1/169395
- http://www.mandriva.com/security/advisories?name=MDKSA-2002:005
- http://www.mandriva.com/security/advisories?name=MDKSA-2002:005