Back

HIGH

vsftpd: memory leak when deny_file option is set

Published May 22, 2008

Description

Memory leak in a certain Red Hat patch, applied to vsftpd 2.0.5 on Red Hat Enterprise Linux (RHEL) 5 and Fedora 6 through 8, and on Foresight Linux and rPath appliances, allows remote attackers to cause a denial of service (memory consumption) via a large number of CWD commands, as demonstrated by an attack on a daemon with the deny_file configuration option.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (2)

References (21)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published May 22, 2008
Updated Aug 7, 2024
Reserved Nov 14, 2007
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date May 21, 2008