PT-2004-2100 · Ipswitch · Ws Ftp Server

Reed Arvin

·

Published

2004-12-08

·

Updated

2017-07-11

·

CVE-2004-1135

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions: WS FTP Server version 5.03 2004.10.14
Description: The issue is related to multiple buffer overflows that can be triggered by remote attackers, causing a denial of service (service crash). This can be achieved by sending long commands, specifically the (1) SITE, (2) XMKD, (3) MKD, and (4) RNFR commands.
Recommendations: For WS FTP Server version 5.03 2004.10.14, consider restricting access to the SITE, XMKD, MKD, and RNFR commands until a patch is available. As a temporary workaround, limiting the length of input for these commands may help minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-1135

Affected Products

Ws Ftp Server