WU-FTPD wu_fnmatch() Function File Globbing Remote DoS

High Nessus Plugin ID 17602


The remote FTP server has a denial of service vulnerability.


The version of WU-FTPD running on the remote host exhausts all available resources on the server when it repeatedly receives the following command :

LIST *****[...]*.*

This issue has been confirmed in WU-FTPD 2.6.2 and earlier.


Apply the latest vendor patches.

See Also


Plugin Details

Severity: High

ID: 17602

File Name: wu_ftpd_glob2.nasl

Version: $Revision: 1.18 $

Type: remote

Family: FTP

Published: 2005/03/23

Modified: 2015/12/23

Dependencies: 10092, 10079

Risk Information

Risk Factor: High


Base Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Information

Vulnerability Publication Date: 2005/02/25

Reference Information

CVE: CVE-2005-0256

OSVDB: 14203

CWE: 119