{"id":"PYSEC-2010-24","details":"The ftp_STOU function in FTPServer.py in pyftpdlib before 0.2.0 does not limit the number of attempts to discover a unique filename, which might allow remote authenticated users to cause a denial of service via a STOU command.","aliases":["CVE-2007-6740","GHSA-cx59-cp6c-9fr8"],"modified":"2023-11-08T03:56:49.963389Z","published":"2010-10-19T20:00:00Z","references":[{"type":"WEB","url":"http://code.google.com/p/pyftpdlib/source/detail?r=37"},{"type":"WEB","url":"http://code.google.com/p/pyftpdlib/source/diff?spec=svn37&r=37&format=side&path=/trunk/pyftpdlib/FTPServer.py"},{"type":"WEB","url":"http://code.google.com/p/pyftpdlib/source/browse/trunk/HISTORY"},{"type":"WEB","url":"http://code.google.com/p/pyftpdlib/issues/detail?id=25"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-cx59-cp6c-9fr8"}],"affected":[{"package":{"name":"pyftpdlib","ecosystem":"PyPI","purl":"pkg:pypi/pyftpdlib"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.2.0"}]}],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/pyftpdlib/PYSEC-2010-24.yaml"}}],"schema_version":"1.7.3"}