Before applying this update, make sure all previously-released errata
relevant to your system have been applied.
This update is available via the Red Hat Network. Details on how to
use the Red Hat Network to apply this update are available at
https://access.redhat.com/kb/docs/DOC-11259
vsftpd (Very Secure File Transfer Protocol (FTP) daemon) is a secure FTP
server for Linux, UNIX, and similar operating systems.
A flaw was discovered in the way vsftpd processed file name patterns. An
FTP user could use this flaw to cause the vsftpd process to use an
excessive amount of CPU time, when processing a request with a
specially-crafted file name pattern. (CVE-2011-0762)
All vsftpd users should upgrade to this updated package, which contains a
backported patch to correct this issue. The vsftpd daemon must be restarted
for this update to take effect.
https://access.redhat.com/security/cve/CVE-2011-0762 https://access.redhat.com/security/updates/classification/#important
Red Hat Enterprise Linux AS version 4:
Source:
i386:
vsftpd-2.0.1-9.el4.i386.rpm
vsftpd-debuginfo-2.0.1-9.el4.i386.rpm
ia64:
vsftpd-2.0.1-9.el4.ia64.rpm
vsftpd-debuginfo-2.0.1-9.el4.ia64.rpm
ppc:
vsftpd-2.0.1-9.el4.ppc.rpm
vsftpd-debuginfo-2.0.1-9.el4.ppc.rpm
s390:
vsftpd-2.0.1-9.el4.s390.rpm
vsftpd-debuginfo-2.0.1-9.el4.s390.rpm
s390x:
vsftpd-2.0.1-9.el4.s390x.rpm
vsftpd-debuginfo-2.0.1-9.el4.s390x.rpm
x86_64:
vsftpd-2.0.1-9.el4.x86_64.rpm
vsftpd-debuginfo-2.0.1-9.el4.x86_64.rpm
Red Hat Enterprise Linux ES version 4:
Source:
i386:
vsftpd-2.0.1-9.el4.i386.rpm
vsftpd-debuginfo-2.0.1-9.el4.i386.rpm
ia64:
vsftpd-2.0.1-9.el4.ia64.rpm
vsftpd-debuginfo-2.0.1-9.el4.ia64.rpm
x86_64:
vsftpd-2.0.1-9.el4.x86_64.rpm
vsftpd-debuginfo-2.0.1-9.el4.x86_64.rpm
RHEL Desktop Workstation (v. 5 client):
Source:
i386:
vsftpd-2.0.5-16.el5_6.1.i386.rpm
vsftpd-debuginfo-2.0.5-16.el5_6.1.i386.rpm
x86_64:
vsftpd-2.0.5-16.el5_6.1.x86_64.rpm
vsftpd-debuginfo-2.0.5-16.el5_6.1.x86_64.rpm
Red Hat Enterprise Linux (v. 5 server):
Source:
i386:
vsftpd-2.0.5-16.el5_6.1.i386.rpm
vsftpd-debuginfo-2.0.5-16.el5_6.1.i386.rpm
ia64:
vsftpd-2.0.5-16.el5_6.1.ia64.rpm
vsftpd-debuginfo-2.0.5-16.el5_6.1.ia64.rpm
ppc:
vsftpd-2.0.5-16.el5_6.1.ppc.rpm
vsftpd-debuginfo-2.0.5-16.el5_6.1.ppc.rpm
s390x:
Read the Full Advisory
An updated vsftpd package that fixes one security issue is now availablefor Red Hat Enterprise Linux 4, 5, and 6.The Red Hat Security Response Team has rated this update as havingimportant security impact. A Common Vulnerability Scoring System (CVSS)base score, which gives a detailed severity rating, is available from theCVE link in the References section.
RHEL Desktop Workstation (v. 5 client) - i386, x86_64
Red Hat Enterprise Linux (v. 5 server) - i386, ia64, ppc, s390x, x86_64
Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, s390, s390x, x86_64
Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64
Red Hat Enterprise Linux Server (v. 6) - i386, ppc64, s390x, x86_64
Red Hat Enterprise Linux Workstation (v. 6) - i386, x86_64
681667 - CVE-2011-0762 vsftpd: remote DoS via crafted glob pattern
Get the latest Linux and open source security news straight to your inbox.