PT-2004-1479 · Typsoft · Typsoft Ftp Server
Intuit
·
Publicado
2004-03-18
·
Atualizado
2017-07-11
·
CVE-2004-0325
CVSS v2.0
2.1
Baixa
| Vetor | AV:L/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
TYPSoft FTP Server version 1.10
Description
The issue allows remote authenticated users to cause a denial of service, specifically CPU consumption, by providing certain arguments to various FTP commands. These commands include mkd, xmkd, dele, size, retr, stor, appe, rnfr, rnto, rmd, and xrmd. The denial of service can be triggered using arguments like "//../" followed by arbitrary characters, such as "//../qwerty".
Recommendations
For TYPSoft FTP Server version 1.10, consider restricting or validating user input for the affected FTP commands to prevent the denial of service. As a temporary workaround, limit the ability of authenticated users to execute these commands with suspicious arguments until a more permanent fix is available.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Typsoft Ftp Server