PT-2004-2782 · Ipswitch · Ipswitch Ws Ftp Server
Hugh Mann
·
Published
2004-12-31
·
Updated
2023-10-11
·
CVE-2004-1883
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Ipswitch WS FTP Server version 4.0.2
Description
The issue involves multiple buffer overflows that allow remote authenticated users to execute arbitrary code. This can be achieved by causing a large error string to be generated by the ALLO handler or by inserting a long hostname or username into a reply to a STAT command while a file is being transferred.
Recommendations
For Ipswitch WS FTP Server version 4.0.2, consider disabling the ALLO handler and restricting access to the STAT command as temporary workarounds until a patch is available. Restrict access to the server to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ipswitch Ws Ftp Server