CVE-2015-5917

MEDIUM

Description

The glob implementation in tnftpd (formerly lukemftpd), as used in Apple OS X before 10.11, allows remote attackers to cause a denial of service (memory consumption and daemon outage) via a STAT command containing a crafted pattern, as demonstrated by multiple instances of the {..,..,..}/* substring.

References

http://lists.apple.com/archives/security-announce/2015/Sep/msg00008.html

http://www.securityfocus.com/bid/76908

http://www.securitytracker.com/id/1033703

https://cxsecurity.com/issue/WLB-2013040082

https://support.apple.com/HT205267

https://www.youtube.com/watch?v=MBK4QYkUm10

Details

Source: MITRE

Published: 2015-10-09

Updated: 2016-12-08

Type: CWE-119

Risk Information

CVSS v2.0

Base Score: 5

Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Impact Score: 2.9

Exploitability Score: 10

Severity: MEDIUM