FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2005-0256

This CVE name corresponds to:

Entered Topic
2005-04-04 wu-ftpd -- remote globbing DoS vulnerability

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2005-0256
Phase Assigned(20050209)

Description

The wu_fnmatch function in wu_fnmatch.c in wu-ftpd 2.6.1 and 2.6.2 allows remote attackers to cause a denial of service (CPU exhaustion by recursion) via a glob pattern with a large number of * (wildcard) characters, as demonstrated using the dir command.

References

Source Reference
IDEFENSE 20050225 WU-FTPD File Globbing Denial of Service Vulnerability
DEBIAN DSA-705
HP HPSBUX02110
HP SSRT061110
SCO SCOSA-2005.63
SUNALERT 57795
SUNALERT 101699
VUPEN ADV-2005-0588
VUPEN ADV-2006-1271
OSVDB 14203
OVAL oval:org.mitre.oval:def:1265
OVAL oval:org.mitre.oval:def:1333
OVAL oval:org.mitre.oval:def:1762
SECUNIA 18210
SECUNIA 14411
SECUNIA 19561