PT-2004-2581 · Rhinosoft · Serv-U Ftp Server
Patrick
·
Published
2004-09-11
·
Updated
2020-07-28
·
CVE-2004-1675
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Serv-U FTP server versions 4.x through 5.x
Description
The issue allows remote attackers to cause a denial of service, resulting in an application crash. This can be achieved by sending a STORE UNIQUE (STOU) command with specific MS-DOS device name arguments, such as
COM1, LPT1, PRN, or AUX.Recommendations
For Serv-U FTP server versions 4.x through 5.x, consider disabling the STORE UNIQUE (STOU) command as a temporary workaround until a patch is available. Restrict access to the server to minimize the risk of exploitation.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Serv-U Ftp Server