glFTPD 1.23 allows remote attackers to cause a denial of service (CPU consumption) via a LIST command with an argument that contains a large number of * (asterisk) characters.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Glftpd | Glftpd | 1.13.6 (including) | 1.13.6 (including) |
Glftpd | Glftpd | 1.16.9 (including) | 1.16.9 (including) |
Glftpd | Glftpd | 1.17.2 (including) | 1.17.2 (including) |
Glftpd | Glftpd | 1.18a (including) | 1.18a (including) |
Glftpd | Glftpd | 1.19 (including) | 1.19 (including) |
Glftpd | Glftpd | 1.20 (including) | 1.20 (including) |
Glftpd | Glftpd | 1.21 (including) | 1.21 (including) |
Glftpd | Glftpd | 1.22b (including) | 1.22b (including) |
Glftpd | Glftpd | 1.23 (including) | 1.23 (including) |