[prev in list] [next in list] [prev in thread] [next in thread]
List: oss-security
Subject: [oss-security] CVE-2008-2375 older vsftpd authentication memory leak
From: Mark J Cox <mjc () redhat ! com>
Date: 2008-06-30 8:45:05
Message-ID: 0806300916560.26198 () mjc ! redhat ! com
[Download RAW message or body]
Customers reported that the pre 2.0.5 versions of vsftpd as shipped in Red
Hat Enterprise Linux 3 and 4 when used in combination with PAM had a
memory leak on an invalid authentication attempt. Since upstream vsftpd
prior to 2.0.5 allows any number of invalid attempts on the same
connection this memory leak could lead to an eventual DoS. I've allocated
this CVE-2008-2375.
Upstream vsftpd 2.0.5 changed its behaviour so that 3 (configurable)
invalid password attempts would close the connection (hence allowing
easier detection of brute forcing attacks etc), and this therefore also
stops any memory leak from leading to a DoS. So we're going to add this
backported patch to our older vsftpd versions:
https://bugzilla.redhat.com/attachment.cgi?id=201051
No embargo on this, the CVE only applies to other distros that are
supporting vsftpd < 2.0.5 and have a memory leak. We also didn't yet
chase down the root cause of the leak since it's mitigated by the patch.
Thanks, Mark
--
Mark J Cox / Red Hat Security Response Team
[prev in list] [next in list] [prev in thread] [next in thread]
Configure |
About |
News |
Add a list |
Sponsored by KoreLogic