Direct naar de inhoud
Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
CVE's Videos

← Terug naar CVE-database

CVE-2015-5917

MEDIUM · 5.0 CVSS Gepubliceerd: CWE-119

Beschrijving NL

De glob-implementatie in tnftpd (voorheen lukemftpd), zoals gebruikt in Apple OS X vóór 10.11, stelt externe aanvallers in STAAT om een denial of service (geheugenverbruik en daemon-uitval) te veroorzaken via een STAT-opdracht met een bewerkt patroon, zoals blijkt uit meerdere exemplaren van de {..,..,..}/* substring.

Origineel (Engels) tonen

The glob implementation in tnftpd (formerly lukemftpd), as used in Apple OS X before 10.11, allows remote attackers to cause a denial of service (memory consumption and daemon outage) via a STAT command containing a crafted pattern, as demonstrated by multiple instances of the {..,..,..}/* substring.

Vendors

Netbsd Apple

Affected products

Tnftpd Mac Os X

References