← All CVEs

CVE-2011-0762

medium · 4

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

The vsf_filename_passes_filter function in ls.c in vsftpd before 2.3.3 allows remote authenticated users to cause a denial of service (CPU consumption and process slot exhaustion) via crafted glob expressions in STAT commands in multiple FTP sessions, a different vulnerability than CVE-2010-2632.

4
CVSS
73.9%
EPSS (exploit prob.)
99th
EPSS percentile
2011-03-02
Published

AV:N/AC:L/Au:S/C:N/I:N/A:P

Weaknesses

CWE-400

Affected products

VendorProductAffected versions
vsftpd_projectvsftpd< 2.3.3
canonicalubuntu_linux6.06
canonicalubuntu_linux8.04
canonicalubuntu_linux9.10
canonicalubuntu_linux10.04
canonicalubuntu_linux10.10
fedoraprojectfedora13
fedoraprojectfedora14
fedoraprojectfedora15
debiandebian_linux5.0
debiandebian_linux6.0
debiandebian_linux7.0
opensuseopensuse11.2
opensuseopensuse11.3
opensuseopensuse11.4
suselinux_enterprise_server9
suselinux_enterprise_server10
suselinux_enterprise_server10
suselinux_enterprise_server11

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2011-0762