A vulnerability has been identified in vsftpd, which could be exploited by attackers or malicious users to cause a denial of service. This issue is caused due to the application not freeing allocated memory when processing user-supplied commands while the "deny_file" option is enabled via the "vsftpd.conf" configuration file, which could be exploited by authenticated or anonymous users to cause a vulnerable server to exhaust all available memory resources, creating a denial of service condition.
Note: A second issue related to the handling of a large number of invalid authentication attempts within the same session could also be exploited to cause a denial of service.
Credits
Vulnerability reported by Martin Nagy.
ChangeLog
2008-05-21 : Initial release
2008-05-22 : Updated Description
Vulnerability Management
Subscribe to FrSIRT VNS and receive real-time e-mail and SMS alerts when new vulnerabilities, exploits, or patches relevant to your systems and network configurations are available.
Feedback
If you have additional information or corrections for this security advisory please submit them via our contact form or by email to updates@frsirt.com.