PT-2007-7139 · Netkit · Netkit-Ftp

Publicado

2007-12-06

·

Atualizado

2009-09-15

·

CVE-2007-6263

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions netkit-ftpd version 0.17
Description The issue is related to the dataconn function in ftpd.c, which calls fclose on an uninitialized file stream when certain modifications to support SSL are introduced. This allows remote attackers to cause a denial of service, potentially crashing the daemon, and may have other unspecified impacts via certain FTP over SSL protocol behaviors, such as breaking a passive FTP DATA connection and triggering an error in the server's SSL accept function.
Recommendations For netkit-ftpd version 0.17, consider disabling the SSL support temporarily as a workaround to minimize the risk of exploitation until a patch is available.

Exploit

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2007-6263

Produtos afetados

Netkit-Ftp