>> HP Security Update Fixes Wu-ftp Remote Denial of Service Vulnerability
Title : HP Security Update Fixes Wu-ftp Remote Denial of Service Vulnerability VUPEN ID : VUPEN/ADV-2006-1271 CVE ID : CVE-2005-0256 CWE ID : CWE-OVAL1762 - CWE-OVAL1333 - CWE-OVAL1265
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-04-07
Technical Description
A vulnerability has been identified in wu-ftpd for HP-UX, which may be exploited by attackers to cause a denial of service. This flaw is due to an input validation error in the "wu_fnmatch()" function [wu_fnmatch.c] when processing a pattern containing the "*" character, which could be exploited by malicious users to cause a denial of service. For additional information, see : VUPEN/ADV-2005-0588