USN-1098-1: vsftpd vulnerability
29 March 2011
An attacker could send crafted input to vsftpd and cause it to crash.
Releases
Packages
- vsftpd - lightweight, efficient FTP server written for security
Details
It was discovered that vsftpd incorrectly handled certain glob expressions.
A remote authenticated user could use a crafted glob expression to cause
vftpd to consume all resources, leading to a denial of service.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 9.10
Ubuntu 8.04
Ubuntu 6.06
Ubuntu 10.10
Ubuntu 10.04
In general, a standard system update will make all the necessary changes.