CVE-2011-0762 affects vsftpd before 2.3.3. The vulnerability is in the vsf_filename_passes_filter function in ls.c, where crafted glob expressions supplied through FTP STAT commands can trigger excessive processing. A remote authenticated user can open multiple FTP sessions and issue malicious STAT requests containing specially crafted glob patterns, causing disproportionate CPU usage and exhausting available process slots. This results in a denial-of-service condition. The issue is distinct from CVE-2010-2632.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a proof-of-concept exploit for CVE-2011-0762, targeting vulnerable FTP servers. The exploit is implemented in C (cve-2011-0762.c) and is designed to connect to a specified FTP server (host and port), authenticate (using provided or default credentials), and repeatedly send a specially crafted STAT command with a deeply nested curly-brace payload. This malformed command aims to trigger a memory corruption or crash in the target FTP server. The exploit does not provide a shell or code execution, but rather demonstrates the vulnerability by causing a denial of service or instability in the server. The repository includes a README.md with usage instructions and references. The main attack vector is network-based, targeting the FTP service (typically on TCP port 21). No hardcoded IP addresses or domains are present; the target is specified at runtime.
This repository contains a single Metasploit auxiliary module targeting a Denial of Service (DoS) vulnerability in VSFTPD versions 2.3.2 and earlier (CVE-2011-0762). The module is written in Ruby and is structured according to Metasploit conventions, inheriting from Msf::Auxiliary and including relevant mixins for remote FTP exploitation and DoS attacks. The exploit works by connecting to the target FTP server and sending a specially crafted STAT command with a large, malformed payload, which causes the VSFTPD service to crash. The module includes a check method to verify if the target is running a vulnerable version of VSFTPD before attempting the attack. The only fingerprintable endpoint is the FTP service (typically port 21/tcp) on the target. The repository is operational in maturity, as it provides a working DoS exploit but does not include advanced payload customization. The code is not a detection script or a fake exploit, and is intended for use within the Metasploit framework.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.