Vulnerabilities > CVE-2008-7265 - Resource Management Errors vulnerability in Proftpd

047910
CVSS 4.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
SINGLE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
PARTIAL
network
low complexity
proftpd
CWE-399
nessus

Summary

The pr_data_xfer function in ProFTPD before 1.3.2rc3 allows remote authenticated users to cause a denial of service (CPU consumption) via an ABOR command during a data transfer.

Common Weakness Enumeration (CWE)

Nessus

  • NASL familyDebian Local Security Checks
    NASL idDEBIAN_DSA-2191.NASL
    descriptionSeveral vulnerabilities have been discovered in ProFTPD, a versatile, virtual-hosting FTP daemon : - CVE-2008-7265 Incorrect handling of the ABOR command could lead to denial of service through elevated CPU consumption. - CVE-2010-3867 Several directory traversal vulnerabilities have been discovered in the mod_site_misc module. - CVE-2010-4562 A SQL injection vulnerability was discovered in the mod_sql module.
    last seen2020-03-17
    modified2011-03-15
    plugin id52660
    published2011-03-15
    reporterThis script is Copyright (C) 2011-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/52660
    titleDebian DSA-2191-1 : proftpd-dfsg - several vulnerabilities
  • NASL familyFTP
    NASL idPROFTPD_1_3_2_RC3.NASL
    descriptionThe remote host is using ProFTPD, a free FTP server for Unix and Linux. According to its banner, the version of ProFTPD installed on the remote host is earlier than 1.3.2rc3 and is affected by a Denial of Service vulnerability via an ABOR command during a data transfer.
    last seen2020-06-01
    modified2020-06-02
    plugin id106751
    published2018-02-12
    reporterThis script is Copyright (C) 2018-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/106751
    titleProFTPD < 1.3.2rc3 ABOR Denial of Service