glFTPD 1.23 allows remote attackers to cause a denial of service (CPU consumption) via a LIST command with an argument that contains a large number of * (asterisk) characters.
2001-08-31T04:00:00.000
2025-04-03T01:03:51.193
Deferred
CVSSv2: 5.0 (MEDIUM)
AV:N/AC:L/Au:N/C:N/I:N/A:P
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | glftpd | glftpd | 1.13.6 | Yes |
Application | glftpd | glftpd | 1.16.9 | Yes |
Application | glftpd | glftpd | 1.17.2 | Yes |
Application | glftpd | glftpd | 1.18a | Yes |
Application | glftpd | glftpd | 1.19 | Yes |
Application | glftpd | glftpd | 1.20 | Yes |
Application | glftpd | glftpd | 1.21 | Yes |
Application | glftpd | glftpd | 1.22b | Yes |
Application | glftpd | glftpd | 1.23 | Yes |