CVE Vulnerabilities

CVE-2008-7263

Improper Authentication

Published: Oct 19, 2010 | Modified: Oct 20, 2010
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

ftpserver.py in pyftpdlib before 0.5.0 does not delay its response after receiving an invalid login attempt, which makes it easier for remote attackers to obtain access via a brute-force attack.

Weakness

When an actor claims to have a given identity, the software does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Pyftpdlib G.rodola 0.1 0.1
Pyftpdlib G.rodola 0.1.1 0.1.1
Pyftpdlib G.rodola 0.2.0 0.2.0
Pyftpdlib G.rodola 0.3.0 0.3.0
Pyftpdlib G.rodola * 0.4.0

Potential Mitigations

References