PT-2004-2933 · Mollensoft · Mollensoft Lightweight Ftp Server

Chintan Trivedi

·

Published

2004-03-24

·

Updated

2017-07-11

·

CVE-2004-2037

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Mollensoft Lightweight FTP Server version 3.6
Description The issue is a buffer overflow that can be triggered by remote authenticated users, potentially leading to a denial of service (crash) and possibly the execution of arbitrary code. This can be achieved by sending a long CWD command, for example, by using the "cd" command in an interactive FTP client.
Recommendations For Mollensoft Lightweight FTP Server version 3.6, consider restricting access to the CWD command as a temporary workaround until a patch is available. Avoid using long commands in the FTP client to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-2037

Affected Products

Mollensoft Lightweight Ftp Server