CVE
- Id
- 83194
- CVE No.
- CVE-2015-5917
- Status
- Candidate
- Description
- The glob implementation in tnftpd (formerly lukemftpd), as used in Apple OS X before 10.11, allows remote attackers to cause a denial of service (memory consumption and daemon outage) via a STAT command containing a crafted pattern, as demonstrated by multiple instances of the {..,..,..}/* substring.
- Phase
- Assigned (20150806)
- Votes
- None (candidate not yet proposed)
- Comments