Back

MEDIUM

openssh: remote DoS in sftp via crafted glob expressions

Published Mar 2, 2011

Description

The (1) remote_glob function in sftp-glob.c and the (2) process_put function in sftp.c in OpenSSH 5.8 and earlier, as used in FreeBSD 7.3 and 8.1, NetBSD 5.0.2, OpenBSD 4.7, and other products, allow remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in SSH_FXP_STAT requests to an sftp daemon, a different vulnerability than CVE-2010-2632.

Affected products

Remediation

Red Hat statement

We do not consider a denial of service flaw in a client application such as sftp to be a security issue.

Metrics

Weaknesses (1)

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Mar 2, 2011
Updated Aug 7, 2024
Reserved Mar 2, 2011
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity n/a
Public date Jan 3, 2011