Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 463238 - net-ftp/tnftp: GLOB_LIMIT Resource Exhaustion Denial of Service Security Issue (CVE-2010-2632)
Summary: net-ftp/tnftp: GLOB_LIMIT Resource Exhaustion Denial of Service Security Issu...
Status: RESOLVED INVALID
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://secunia.com/advisories/52727/
Whiteboard: B3 [ebuild+]
Keywords:
Depends on:
Blocks:
 
Reported: 2013-03-25 15:28 UTC by Agostino Sarubbo
Modified: 2013-09-17 21:44 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2013-03-25 15:28:19 UTC
From ${URL} :

Description
A security issue has been reported in tnftpd, which can be exploited by malicious users to cause a 
DoS (Denial of Service).

The security issue is caused due to an insufficient GLOB_LIMIT implementation, which can be 
exploited to exhaust memory or cause a high CPU load via specially crafted patterns in commands 
passed to e.g. the ftpd server process.

This is related to:
SA41694

The security issue is reported in version 20100324. Prior versions may also be affected.


Solution
Update to version 20130322.
Original Advisory
http://freecode.com/projects/tnftpd/releases/353302
Comment 1 Chris Reffett (RETIRED) gentoo-dev Security 2013-09-17 00:36:04 UTC
Ping, need a bump.
Comment 2 Chris Reffett (RETIRED) gentoo-dev Security 2013-09-17 21:44:11 UTC
Wait, hold on. This is for tnftpd, not tnftp. We don't appear to ship tnftpd. Closing INVALID.