CVE-2011-0418

medium
Published 2011-05-24 ยท Modified 2026-04-29
CVSS v3
โ€”
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
5.0

Description

The glob implementation in Pure-FTPd before 1.0.32, and in libc in NetBSD 5.1, does not properly expand expressions containing curly brackets, which allows remote authenticated users to cause a denial of service (memory consumption) via a crafted FTP STAT command.

Predictions

Exploit likelihood
20%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No mitigations published for this CVE yet.

The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ€” if you've already worked around this in production โ€” publish your fix to the community-verified tier.

โœš Propose a mitigation on Community โ†’ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here with source_tier=community-verified.

Exploits

Public proof-of-concept code below. AS-IS, for defenders and authorised testing only.

Exploit-DB

EDB-24450 dos freebsd
Maksymilian Arciemowicz ยท 2013-02-05

FreeBSD 9.1 - 'ftpd' Remote Denial of Service

Source code queued for fetch โ€” refresh in a moment.

OS impact

freebsd FreeBSD Affected 1 release
VersionStatusFixed in
5.1 Affected โ€”
debian Debian Fixed 4 releases
VersionStatusFixed in
trixie Fixed 1.0.32-1
sid Fixed 1.0.32-1
bullseye Fixed 1.0.32-1
bookworm Fixed 1.0.32-1

Application impact

VendorProductVersionsFixed
pureftpdpure-ftpd{"endIncluding":"1.0.31"}
pureftpdpure-ftpd0.90
pureftpdpure-ftpd0.91
pureftpdpure-ftpd0.92
pureftpdpure-ftpd0.93
pureftpdpure-ftpd0.94
pureftpdpure-ftpd0.95
pureftpdpure-ftpd0.95-pre1
pureftpdpure-ftpd0.95-pre2
pureftpdpure-ftpd0.95-pre3
pureftpdpure-ftpd0.95-pre4
pureftpdpure-ftpd0.95.1
pureftpdpure-ftpd0.95.2
pureftpdpure-ftpd0.96
pureftpdpure-ftpd0.96.1
pureftpdpure-ftpd0.96pre1
pureftpdpure-ftpd0.97-final
pureftpdpure-ftpd0.97.1
pureftpdpure-ftpd0.97.2
pureftpdpure-ftpd0.97.3
pureftpdpure-ftpd0.97.4
pureftpdpure-ftpd0.97.5
pureftpdpure-ftpd0.97.6
pureftpdpure-ftpd0.97.7
pureftpdpure-ftpd0.97.7pre1
pureftpdpure-ftpd0.97.7pre2
pureftpdpure-ftpd0.97.7pre3
pureftpdpure-ftpd0.97pre1
pureftpdpure-ftpd0.97pre2
pureftpdpure-ftpd0.97pre3
pureftpdpure-ftpd0.97pre4
pureftpdpure-ftpd0.97pre5
pureftpdpure-ftpd0.98-final
pureftpdpure-ftpd0.98.1
pureftpdpure-ftpd0.98.2
pureftpdpure-ftpd0.98.2a
pureftpdpure-ftpd0.98.3
pureftpdpure-ftpd0.98.4
pureftpdpure-ftpd0.98.5
pureftpdpure-ftpd0.98.6
pureftpdpure-ftpd0.98.7
pureftpdpure-ftpd0.98pre1
pureftpdpure-ftpd0.98pre2
pureftpdpure-ftpd0.99
pureftpdpure-ftpd0.99.1
pureftpdpure-ftpd0.99.1a
pureftpdpure-ftpd0.99.1b
pureftpdpure-ftpd0.99.2
pureftpdpure-ftpd0.99.2a
pureftpdpure-ftpd0.99.3
pureftpdpure-ftpd0.99.4
pureftpdpure-ftpd0.99.9
pureftpdpure-ftpd0.99a
pureftpdpure-ftpd0.99b
pureftpdpure-ftpd0.99pre1
pureftpdpure-ftpd0.99pre2
pureftpdpure-ftpd1.0.0
pureftpdpure-ftpd1.0.1
pureftpdpure-ftpd1.0.2
pureftpdpure-ftpd1.0.3
pureftpdpure-ftpd1.0.4
pureftpdpure-ftpd1.0.5
pureftpdpure-ftpd1.0.6
pureftpdpure-ftpd1.0.7
pureftpdpure-ftpd1.0.8
pureftpdpure-ftpd1.0.9
pureftpdpure-ftpd1.0.10
pureftpdpure-ftpd1.0.11
pureftpdpure-ftpd1.0.12
pureftpdpure-ftpd1.0.13a
pureftpdpure-ftpd1.0.14
pureftpdpure-ftpd1.0.15
pureftpdpure-ftpd1.0.16a
pureftpdpure-ftpd1.0.16b
pureftpdpure-ftpd1.0.16c
pureftpdpure-ftpd1.0.17
pureftpdpure-ftpd1.0.17a
pureftpdpure-ftpd1.0.18
pureftpdpure-ftpd1.0.19
pureftpdpure-ftpd1.0.20
pureftpdpure-ftpd1.0.21
pureftpdpure-ftpd1.0.22
pureftpdpure-ftpd1.0.24
pureftpdpure-ftpd1.0.25
pureftpdpure-ftpd1.0.26
pureftpdpure-ftpd1.0.27
pureftpdpure-ftpd1.0.28
pureftpdpure-ftpd1.0.29
pureftpdpure-ftpd1.0.30

References

CWEs

CWE-20

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.