CVE-2011-0762 describes a denial-of-service vulnerability in vsftpd versions prior to 2.3.3, affecting various Linux distributions including Debian, Fedora, and openSUSE. Authenticated remote attackers can exploit this by sending crafted glob expressions in STAT commands, leading to high CPU consumption and process slot exhaustion. The vulnerability has a CVSS score of 4.0 (AV:N/AC:L/Au:S/C:N/I:N/A:P), indicating network-based attacks with low complexity requiring authentication, resulting in partial availability impact. While not on the KEV catalog, exploit modules are available in Metasploit and Nuclei, and an ExploitDB entry exists, though there is minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.3.3CPE matchmatch criteria | cpe:2.3:a:vsftpd_project:vsftpd:*:*:*:*:*:*:*:* | ||
6.06CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:*:*:*:* | ||
8.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:8.04:*:*:*:-:*:*:* | ||
9.10CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:9.10:*:*:*:*:*:*:* | ||
10.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:10.04:*:*:*:-:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:S/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.