PT-2004-1024 · Debian · Oftpd
Publicado
2004-04-06
·
Atualizado
2017-07-11
·
CVE-2004-0376
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
oftpd versions 0.3.6 and earlier
Description
The issue affects the oftpd package in Debian GNU/Linux, potentially leading to a disruption in the availability of protected information. This can be exploited remotely. Specifically, a denial of service (crash) can occur via a PORT command with a large value.
Recommendations
For oftpd versions 0.3.6 and earlier, consider restricting access to the PORT command to minimize the risk of exploitation until a patch is available. As a temporary workaround, limiting the size of values accepted by the PORT command may help mitigate the issue.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Oftpd