PT-2004-1453 · Smallftpd · Smallftpd
Intuit
·
Published
2004-03-18
·
Updated
2017-07-11
·
CVE-2004-0299
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
smallftpd version 0.99
Description
The issue is related to a buffer overflow that can be triggered by a local user through an FTP request containing a large number of "/" characters, leading to a denial of service (crash).
Recommendations
For smallftpd version 0.99, consider restricting access to the FTP service until a patch is available to prevent potential denial of service attacks. As a temporary workaround, limiting the size of incoming FTP requests may help mitigate the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Smallftpd