WFTPD Server MLST Argument Remote Denial Of Service Vulnerability
BID:11067
Info
WFTPD Server MLST Argument Remote Denial Of Service Vulnerability
| Bugtraq ID: | 11067 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 30 2004 12:00AM |
| Updated: | Aug 30 2004 12:00AM |
| Credit: | Discovery of this vulnerability is credited to Lion <[email protected]>. |
| Vulnerable: |
Texas Imperial Software WFTPD Pro 3.21 R2 Texas Imperial Software WFTPD Pro 3.21 R3 Texas Imperial Software WFTPD Pro 3.21 R1 Texas Imperial Software WFTPD Pro 3.21 |
| Not Vulnerable: | |
Discussion
WFTPD Server MLST Argument Remote Denial Of Service Vulnerability
WFTPD server is reported to be prone to a denial of service. The issue is reported to present itself if a user who is logged into the affected service issues MLST requests with varying parameter sizes. This will cause the server to behave in an unstable manner potentially preventing normal service.
WFTPD server is reported to be prone to a denial of service. The issue is reported to present itself if a user who is logged into the affected service issues MLST requests with varying parameter sizes. This will cause the server to behave in an unstable manner potentially preventing normal service.
Exploit / POC
WFTPD Server MLST Argument Remote Denial Of Service Vulnerability
The following exploit is available:
The following exploit is available:
Solution / Fix
WFTPD Server MLST Argument Remote Denial Of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
WFTPD Server MLST Argument Remote Denial Of Service Vulnerability
References:
References:
- WFTPD Homepage (Texas Imperial Software)
- WFTPD Pro Server 3.21 MLST DoS Exploit (Lion)
- WFTPD Pro Server 3.21 MLST Command Denial of Service Vulnerability ("lion"
)