PT-2004-1479 · Typsoft · Typsoft Ftp Server
Intuit
·
Published
2004-03-18
·
Updated
2017-07-11
·
CVE-2004-0325
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
TYPSoft FTP Server version 1.10
Description
The issue allows remote authenticated users to cause a denial of service, specifically CPU consumption, by providing certain arguments to various FTP commands. These commands include mkd, xmkd, dele, size, retr, stor, appe, rnfr, rnto, rmd, and xrmd. The denial of service can be triggered using arguments like "//../" followed by arbitrary characters, such as "//../qwerty".
Recommendations
For TYPSoft FTP Server version 1.10, consider restricting or validating user input for the affected FTP commands to prevent the denial of service. As a temporary workaround, limit the ability of authenticated users to execute these commands with suspicious arguments until a more permanent fix is available.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Typsoft Ftp Server