PT-2004-2782 · Ipswitch · Ipswitch Ws Ftp Server

Hugh Mann

·

Published

2004-12-31

·

Updated

2023-10-11

·

CVE-2004-1883

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Ipswitch WS FTP Server version 4.0.2
Description The issue involves multiple buffer overflows that allow remote authenticated users to execute arbitrary code. This can be achieved by causing a large error string to be generated by the ALLO handler or by inserting a long hostname or username into a reply to a STAT command while a file is being transferred.
Recommendations For Ipswitch WS FTP Server version 4.0.2, consider disabling the ALLO handler and restricting access to the STAT command as temporary workarounds until a patch is available. Restrict access to the server to minimize the risk of exploitation.

Exploit

Fix

Related Identifiers

CVE-2004-1883

Affected Products

Ipswitch Ws Ftp Server