Medium severity6.5NVD Advisory· Published Jan 14, 2026· Updated Apr 15, 2026
CVE-2025-14242
CVE-2025-14242
Description
A flaw was found in vsftpd. This vulnerability allows a denial of service (DoS) via an integer overflow in the ls command parameter parsing, triggered by a remote, authenticated attacker sending a crafted STAT command with a specific byte sequence.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
14- access.redhat.com/errata/RHSA-2026:0605nvd
- access.redhat.com/errata/RHSA-2026:0606nvd
- access.redhat.com/errata/RHSA-2026:0608nvd
- access.redhat.com/errata/RHSA-2026:4470nvd
- access.redhat.com/errata/RHSA-2026:4477nvd
- access.redhat.com/errata/RHSA-2026:4513nvd
- access.redhat.com/errata/RHSA-2026:4522nvd
- access.redhat.com/errata/RHSA-2026:4525nvd
- access.redhat.com/errata/RHSA-2026:4543nvd
- access.redhat.com/errata/RHSA-2026:4550nvd
- access.redhat.com/errata/RHSA-2026:4553nvd
- access.redhat.com/errata/RHSA-2026:4554nvd
- access.redhat.com/security/cve/CVE-2025-14242nvd
- bugzilla.redhat.com/show_bug.cginvd
News mentions
0No linked articles in our index yet.