TYPSoft FTP Server Remote 'RETR' Command Denial Of Service Vulnerability
BID:11131
Info
TYPSoft FTP Server Remote 'RETR' Command Denial Of Service Vulnerability
| Bugtraq ID: | 11131 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 30 2004 12:00AM |
| Updated: | Aug 30 2004 12:00AM |
| Credit: | CoolICE <[email protected]> disclosed this vulnerability. |
| Vulnerable: |
TYPSoft TYPSoft FTP Server 1.11 TYPSoft TYPSoft FTP Server 1.10 TYPSoft TYPSoft FTP Server 1.1 TYPSoft TYPSoft FTP Server 1.0 9 TYPSoft TYPSoft FTP Server 1.0 8 TYPSoft TYPSoft FTP Server 1.0 7 TYPSoft TYPSoft FTP Server 1.0 6 TYPSoft TYPSoft FTP Server 1.0 5 TYPSoft TYPSoft FTP Server 1.0 4 TYPSoft TYPSoft FTP Server 1.0 3 TYPSoft TYPSoft FTP Server 1.0 2 TYPSoft TYPSoft FTP Server 1.0 1 TYPSoft TYPSoft FTP Server 1.0 0 TYPSoft TYPSoft FTP Server 0.99.6 TYPSoft TYPSoft FTP Server 0.97.5 TYPSoft TYPSoft FTP Server 0.97 TYPSoft TYPSoft FTP Server 0.96 TYPSoft TYPSoft FTP Server 0.95 TYPSoft TYPSoft FTP Server 0.93 TYPSoft TYPSoft FTP Server 0.85 |
| Not Vulnerable: | |
Discussion
TYPSoft FTP Server Remote 'RETR' Command Denial Of Service Vulnerability
TYPSoft FTP Server is reported susceptible to a remote denial of service vulnerability.
A remote attacker with the ability to successfully authenticate to the affected FTP server is reportedly able to crash the service.
Versions up to and including 1.11 are reportedly affected by this vulnerability.
TYPSoft FTP Server is reported susceptible to a remote denial of service vulnerability.
A remote attacker with the ability to successfully authenticate to the affected FTP server is reportedly able to crash the service.
Versions up to and including 1.11 are reportedly affected by this vulnerability.
Exploit / POC
TYPSoft FTP Server Remote 'RETR' Command Denial Of Service Vulnerability
An exploit is not required, however CoolICE has provided an example script sufficient to exploit this vulnerability:
An exploit is not required, however CoolICE has provided an example script sufficient to exploit this vulnerability:
Solution / Fix
TYPSoft FTP Server Remote 'RETR' Command Denial Of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
TYPSoft FTP Server Remote 'RETR' Command Denial Of Service Vulnerability
References:
References:
- TYPSoft FTP Server Homepage (TYPSoft)
- DOS@TFS ("CoolICE"
)