Lucene search

K
githubGitHub Advisory DatabaseGHSA-CX59-CP6C-9FR8
HistoryMay 01, 2022 - 6:45 p.m.

pyftpdlib vulnerable to allocation of resources without limits

2022-05-0118:45:58
CWE-770
GitHub Advisory Database
github.com
19

4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:N/I:N/A:P

0.002 Low

EPSS

Percentile

59.6%

The ftp_STOU function in FTPServer.py in pyftpdlib before 0.2.0 does not limit the number of attempts to discover a unique filename, which might allow remote authenticated users to cause a denial of service via a STOU command.

Affected configurations

Vulners
Node
g.rodolapyftpdlibRange<0.2.0
CPENameOperatorVersion
pyftpdliblt0.2.0

4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:N/I:N/A:P

0.002 Low

EPSS

Percentile

59.6%