PT-2004-2100 · Ipswitch · Ws Ftp Server
Reed Arvin
·
Published
2004-12-08
·
Updated
2017-07-11
·
CVE-2004-1135
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions:
WS FTP Server version 5.03 2004.10.14
Description:
The issue is related to multiple buffer overflows that can be triggered by remote attackers, causing a denial of service (service crash). This can be achieved by sending long commands, specifically the (1) SITE, (2) XMKD, (3) MKD, and (4) RNFR commands.
Recommendations:
For WS FTP Server version 5.03 2004.10.14, consider restricting access to the SITE, XMKD, MKD, and RNFR commands until a patch is available. As a temporary workaround, limiting the length of input for these commands may help minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ws Ftp Server