CyberRota Analysis
AI-GeneratedThe basic-ftp client for Node.js versions prior to 6.2.1 is vulnerable to a denial-of-service attack, where a malicious FTP server can exploit the Client.list() method to cause excessive CPU consumption through inefficient parsing of directory listings. This vulnerability can lead to the Node.js event loop being blocked, effectively freezing the application. Organizations using basic-ftp in their Node.js applications should prioritize upgrading to version 6.2.1 or later to mitigate this risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
basic-ftp is an FTP client for Node.js. Prior to 6.2.1, Client.list() can be forced by a malicious or compromised FTP server to spend quadratic CPU time parsing a directory listing because the RE_LINE expression in src/parseListUnix.ts backtracks across adjacent variable-length owner and group fields when a long Unix-style line has a valid prefix but cannot satisfy the later size and date fields. parseList() selects a parser from the last nonblank line and then applies it to every line, so a normal final line can select the Unix parser while an earlier crafted line blocks the Node.js event loop and freezes the process. This issue is fixed in version 6.2.1.