The pr_data_xfer function in ProFTPD before 1.3.2rc3 allows remote authenticated users to cause a denial of service (CPU consumption) via an ABOR command during a data transfer.
Weaknesses in this category are related to improper management of system resources.
Link | Tags |
---|---|
http://www.debian.org/security/2011/dsa-2191 | vendor advisory |
http://bugs.proftpd.org/show_bug.cgi?id=3131 | patch |