PT-2008-2216 · Ipswitch · Ipswitch Ws Ftp Server With Ssh
Securfrog
·
Published
2008-02-05
·
Updated
2023-10-11
·
CVE-2008-0590
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Ipswitch WS FTP Server with SSH version 6.1.0.0
Description
The issue allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via a long
opendir command. This can be exploited by sending a long command to the server, potentially leading to a buffer overflow.Recommendations
For Ipswitch WS FTP Server with SSH version 6.1.0.0, consider restricting access to the
opendir command as a temporary workaround until a patch is available. Avoid using long commands that could trigger the buffer overflow until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ipswitch Ws Ftp Server With Ssh