CVE-2025-14242: Vsftpd: vsftpd: denial of service via integer overflow in ls command parameter parsing
A flaw was found in vsftpd. This vulnerability allows a denial of service (DoS) via an integer overflow in the ls command parameter parsing, triggered by a remote, authenticated attacker sending a crafted STAT command with a specific byte sequence.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14242?
CVE-2025-14242 has a severity level rated as high due to its potential to cause denial of service.
How do I fix CVE-2025-14242?
To fix CVE-2025-14242, users should update vsftpd to the latest patched version provided by their vendor.
Who is affected by CVE-2025-14242?
CVE-2025-14242 affects users of the vsftpd software, particularly those allowing remote, authenticated access.
What type of attack does CVE-2025-14242 facilitate?
CVE-2025-14242 facilitates a denial of service attack through an integer overflow during command parameter parsing.
How can I mitigate the risk of CVE-2025-14242?
To mitigate the risk of CVE-2025-14242, restrict access to the vsftpd server and monitor logs for unusual activity.