PT-1997-1099 · Rhinosoft · Ftp Serv-U
Published
1997-07-01
·
Updated
2018-05-03
·
CVE-1999-0219
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
FTP Serv-U version 2.5
Description
A buffer overflow issue allows remote authenticated users to cause a denial of service, resulting in a crash, by sending a long CWD or LS command.
Recommendations
For FTP Serv-U version 2.5, consider restricting access to the CWD and LS commands until a patch is available. As a temporary workaround, limit the length of input for these commands to prevent the buffer overflow.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ftp Serv-U