CVE-2010-3494Race Condition in Pyftpdlib

CWE-362Race Condition18 documents5 sources
Severity
4.3MEDIUMNVD
GHSA5.0OSV5.0
EPSS
0.4%
top 38.31%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 19
Latest updateMay 17

Description

Race condition in the FTPHandler class in ftpserver.py in pyftpdlib before 0.5.2 allows remote attackers to cause a denial of service (daemon outage) by establishing and then immediately closing a TCP connection, leading to the accept function having an unexpected value of None for the address, or an ECONNABORTED, EAGAIN, or EWOULDBLOCK error, a related issue to CVE-2010-3492.

CVSS vector

AV:N/AC:M/C:N/I:N/A:PExploitability: 8.6 | Impact: 2.9

Affected Packages3 packages

PyPIg.rodola/pyftpdlib< 0.5.2+1
debiandebian/python-pyftpdlib< python-pyftpdlib 0.5.2-1 (bookworm)+1
NVDg.rodola/pyftpdlib0.5.1+7

Patches

🔴Vulnerability Details

9
OSV
Concurrent Execution using Shared Resource with Improper Synchronization in pyftpdlib2022-05-17
GHSA
Concurrent Execution using Shared Resource with Improper Synchronization in pyftpdlib2022-05-17
OSV
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') in pyftpdlib2022-05-02
GHSA
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') in pyftpdlib2022-05-02
OSV
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') in pyftpdlib2022-05-02

📋Vendor Advisories

3
Debian
CVE-2010-3494: python-pyftpdlib - Race condition in the FTPHandler class in ftpserver.py in pyftpdlib before 0.5.2...2010
Debian
CVE-2009-5011: python-pyftpdlib - Race condition in the FTPHandler class in ftpserver.py in pyftpdlib before 0.5.2...2009
Debian
CVE-2009-5010: python-pyftpdlib - Race condition in the FTPHandler class in ftpserver.py in pyftpdlib before 0.5.1...2009

💬Community

3
Bugzilla
CVE-2009-5011 CVE-2009-5012 CVE-2009-5013 CVE-2010-3494 pyftpdlib various flaws [fedora-12]2010-10-24
Bugzilla
CVE-2010-3494 pyftpdlib: Race condition in the FTPHandler class in ftpserver.py2010-10-24
Bugzilla
CVE-2009-5011 pyftpdlib: Race condition in the FTPHandler class2010-10-24