PT-2004-1479 · Typsoft · Typsoft Ftp Server

Intuit

·

Published

2004-03-18

·

Updated

2017-07-11

·

CVE-2004-0325

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions TYPSoft FTP Server version 1.10
Description The issue allows remote authenticated users to cause a denial of service, specifically CPU consumption, by providing certain arguments to various FTP commands. These commands include mkd, xmkd, dele, size, retr, stor, appe, rnfr, rnto, rmd, and xrmd. The denial of service can be triggered using arguments like "//../" followed by arbitrary characters, such as "//../qwerty".
Recommendations For TYPSoft FTP Server version 1.10, consider restricting or validating user input for the affected FTP commands to prevent the denial of service. As a temporary workaround, limit the ability of authenticated users to execute these commands with suspicious arguments until a more permanent fix is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-0325

Affected Products

Typsoft Ftp Server