The glob implementation in libc allows authenticated remote users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames. This vulnerability can be exploited against a device running Junos OS with FTP services enabled to launch a high CPU utilization partial denial of service attack. This issue has been assigned CVE-2010-2632.
The following software releases have been updated to resolve this specific issue:
Use access lists or firewall filters to limit access to the router via FTP only from trusted hosts.