PT-2004-1479 · Typsoft · Typsoft Ftp Server

Intuit

·

Publicado

2004-03-18

·

Atualizado

2017-07-11

·

CVE-2004-0325

CVSS v2.0

2.1

Baixa

VetorAV:L/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions TYPSoft FTP Server version 1.10
Description The issue allows remote authenticated users to cause a denial of service, specifically CPU consumption, by providing certain arguments to various FTP commands. These commands include mkd, xmkd, dele, size, retr, stor, appe, rnfr, rnto, rmd, and xrmd. The denial of service can be triggered using arguments like "//../" followed by arbitrary characters, such as "//../qwerty".
Recommendations For TYPSoft FTP Server version 1.10, consider restricting or validating user input for the affected FTP commands to prevent the denial of service. As a temporary workaround, limit the ability of authenticated users to execute these commands with suspicious arguments until a more permanent fix is available.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2004-0325

Produtos afetados

Typsoft Ftp Server