CVE-2010-2632
libc/glob - Resource Exhaustion / Remote ftpd-anonymous (Denial of Service)
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
-Decision
Descriptions
Unspecified vulnerability in the FTP Server in Oracle Solaris 8, 9, 10, and 11 Express allows remote attackers to affect availability. NOTE: the previous information was obtained from the January 2011 CPU. Oracle has not commented on claims from a reliable researcher that this is an issue in the glob implementation in libc that allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames.
Vulnerabilidad no especificada en FTP Server para Oracle Solaris v8, v9, v10, v11 y Express permite a atacantes remotos afectar a la disponibilidad, relacionado con FTP.
The glob(3) function is a pathname generator that implements the rules for file name pattern matching used by the shell. GLOB_LIMIT is supposed to limit the number of paths to prevent against memory or CPU attacks. The implementation however is insufficient. An attacker that is able to exploit this vulnerability could cause excessive memory or CPU usage, resulting in a denial of service.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2010-07-06 CVE Reserved
- 2010-10-07 First Exploit
- 2010-10-08 CVE Published
- 2024-08-07 CVE Updated
- 2025-07-04 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
CAPEC
References (14)
URL | Tag | Source |
---|---|---|
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10598 | X_refsource_confirm | |
http://secunia.com/advisories/42984 | Third Party Advisory | |
http://secunia.com/advisories/43433 | Third Party Advisory | |
http://secunia.com/advisories/55212 | Third Party Advisory | |
http://securityreason.com/achievement_securityalert/89 | Third Party Advisory | |
http://securityreason.com/achievement_securityalert/97 | Third Party Advisory | |
http://www.securitytracker.com/id?1024975 | Vdb Entry | |
http://www.vupen.com/english/advisories/2011/0151 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/64798 | Vdb Entry | |
https://support.avaya.com/css/P8/documents/100127892 | X_refsource_confirm |
URL | Date | SRC |
---|---|---|
https://packetstorm.news/files/id/120032 | 2013-02-02 | |
https://packetstorm.news/files/id/94556 | 2010-10-08 | |
https://www.exploit-db.com/exploits/15215 | 2010-10-07 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.oracle.com/technetwork/topics/security/cpujan2011-194091.html | 2017-08-17 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Sun Search vendor "Sun" | Sunos Search vendor "Sun" for product "Sunos" | 5.8 Search vendor "Sun" for product "Sunos" and version "5.8" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Sunos Search vendor "Sun" for product "Sunos" | 5.9 Search vendor "Sun" for product "Sunos" and version "5.9" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Sunos Search vendor "Sun" for product "Sunos" | 5.10 Search vendor "Sun" for product "Sunos" and version "5.10" | - |
Affected
| ||||||
Sun Search vendor "Sun" | Sunos Search vendor "Sun" for product "Sunos" | 5.11 Search vendor "Sun" for product "Sunos" and version "5.11" | express |
Affected
|