PT-2004-1024 · Debian · Oftpd

Publicado

2004-04-06

·

Atualizado

2017-07-11

·

CVE-2004-0376

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions oftpd versions 0.3.6 and earlier
Description The issue affects the oftpd package in Debian GNU/Linux, potentially leading to a disruption in the availability of protected information. This can be exploited remotely. Specifically, a denial of service (crash) can occur via a PORT command with a large value.
Recommendations For oftpd versions 0.3.6 and earlier, consider restricting access to the PORT command to minimize the risk of exploitation until a patch is available. As a temporary workaround, limiting the size of values accepted by the PORT command may help mitigate the issue.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

BDU:2015-03091
CVE-2004-0376
DSA-473

Produtos afetados

Oftpd