RhinoSoft Serv-U FTP Server Remote Denial Of Service Vulnerability
BID:11155
Info
RhinoSoft Serv-U FTP Server Remote Denial Of Service Vulnerability
| Bugtraq ID: | 11155 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 11 2004 12:00AM |
| Updated: | Sep 11 2004 12:00AM |
| Credit: | Discovery is credited to Patrick <[email protected]>. |
| Vulnerable: |
Rhino Software Serv-U 5.2 .0.0 Rhino Software Serv-U 5.1 .0 Rhino Software Serv-U 5.0 .0.9 Rhino Software Serv-U 5.0 .0.6 Rhino Software Serv-U 5.0 .0.4 Rhino Software Serv-U 4.2 Rhino Software Serv-U 4.1 .0.11 Rhino Software Serv-U 4.1 Rhino Software Serv-U 4.0 .0.4 Rhino Software Serv-U 3.1 Rhino Software Serv-U 3.0 |
| Not Vulnerable: |
Rhino Software Serv-U 5.2 .0.1 |
Discussion
RhinoSoft Serv-U FTP Server Remote Denial Of Service Vulnerability
Serv-U FTP Server is reported prone to a denial of service vulnerability. This issue presents itself because the application fails to handle exceptional conditions.
The vulnerability is a result of Serv-U FTP Server processing certain 'STOU' commands.
All versions of Serv-U prior to 5.2.0.1 are reportedly affected by this vulnerability.
Serv-U FTP Server is reported prone to a denial of service vulnerability. This issue presents itself because the application fails to handle exceptional conditions.
The vulnerability is a result of Serv-U FTP Server processing certain 'STOU' commands.
All versions of Serv-U prior to 5.2.0.1 are reportedly affected by this vulnerability.
Exploit / POC
RhinoSoft Serv-U FTP Server Remote Denial Of Service Vulnerability
No exploit is required.
The following proof of concept is available:
STOU COM1
STOU LPT1
STOU PRN
STOU AUX
No exploit is required.
The following proof of concept is available:
STOU COM1
STOU LPT1
STOU PRN
STOU AUX
Solution / Fix
RhinoSoft Serv-U FTP Server Remote Denial Of Service Vulnerability
Solution:
This issue has been addressed with the release of Serv-U 5.2.0.1, which is available to users with a RhinoSoft registration ID.
Rhino Software Serv-U 3.0
Rhino Software Serv-U 3.1
Rhino Software Serv-U 4.0 .0.4
Rhino Software Serv-U 4.1 .0.11
Rhino Software Serv-U 4.1
Rhino Software Serv-U 4.2
Rhino Software Serv-U 5.0 .0.4
Rhino Software Serv-U 5.0 .0.9
Rhino Software Serv-U 5.0 .0.6
Rhino Software Serv-U 5.1 .0
Rhino Software Serv-U 5.2 .0.0
Solution:
This issue has been addressed with the release of Serv-U 5.2.0.1, which is available to users with a RhinoSoft registration ID.
Rhino Software Serv-U 3.0
-
RhinoSoft Serv-U 5.2.0.1
Download requires registration
http://www.serv-u.com/customer/record.asp?prod=su
Rhino Software Serv-U 3.1
-
RhinoSoft Serv-U 5.2.0.1
Download requires registration
http://www.serv-u.com/customer/record.asp?prod=su
Rhino Software Serv-U 4.0 .0.4
-
RhinoSoft Serv-U 5.2.0.1
Download requires registration
http://www.serv-u.com/customer/record.asp?prod=su
Rhino Software Serv-U 4.1 .0.11
-
RhinoSoft Serv-U 5.2.0.1
Download requires registration
http://www.serv-u.com/customer/record.asp?prod=su
Rhino Software Serv-U 4.1
-
RhinoSoft Serv-U 5.2.0.1
Download requires registration
http://www.serv-u.com/customer/record.asp?prod=su
Rhino Software Serv-U 4.2
-
RhinoSoft Serv-U 5.2.0.1
Download requires registration
http://www.serv-u.com/customer/record.asp?prod=su
Rhino Software Serv-U 5.0 .0.4
-
RhinoSoft Serv-U 5.2.0.1
Download requires registration
http://www.serv-u.com/customer/record.asp?prod=su
Rhino Software Serv-U 5.0 .0.9
-
RhinoSoft Serv-U 5.2.0.1
Download requires registration
http://www.serv-u.com/customer/record.asp?prod=su
Rhino Software Serv-U 5.0 .0.6
-
RhinoSoft Serv-U 5.2.0.1
Download requires registration
http://www.serv-u.com/customer/record.asp?prod=su
Rhino Software Serv-U 5.1 .0
-
RhinoSoft Serv-U 5.2.0.1
Download requires registration
http://www.serv-u.com/customer/record.asp?prod=su
Rhino Software Serv-U 5.2 .0.0
-
RhinoSoft Serv-U 5.2.0.1
Download requires registration
http://www.serv-u.com/customer/record.asp?prod=su
References
RhinoSoft Serv-U FTP Server Remote Denial Of Service Vulnerability
References:
References:
- Serv-U Homepage (RhinoSoft)
- Serv-U up to 5.2 Denial of Service (Patrick
)