Fastream NetFile FTP/Web Server HEAD Request Denial Of Service Vulnerability
BID:11687
Info
Fastream NetFile FTP/Web Server HEAD Request Denial Of Service Vulnerability
| Bugtraq ID: | 11687 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 16 2004 12:00AM |
| Updated: | Nov 16 2004 12:00AM |
| Credit: | Discovery of this vulnerability is credited to bratax. |
| Vulnerable: |
Fastream NETFile FTP/Web Server Professional 7.1.2 Fastream NetFILE FTP/Web Server 7.1 Fastream NetFILE FTP/Web Server 6.7.5 Fastream NetFILE FTP/Web Server 6.7.3 Fastream NetFILE FTP/Web Server 6.7.2 .1085 Fastream NetFILE FTP/Web Server 6.5.1 .981 Fastream NetFILE FTP/Web Server 6.5.1 .980 |
| Not Vulnerable: | |
Discussion
Fastream NetFile FTP/Web Server HEAD Request Denial Of Service Vulnerability
Fastream NetFile FTP/Web Server is reported susceptible to an HTTP HEAD request denial of service vulnerability.
This vulnerability allows remote attackers to create many simultaneous HTTP HEAD requests to the vulnerable server application. Once the attacker has created sufficient connections, further requests from legitimate users will reportedly be denied. Due to the failure of the application to close the previous connections, it is conjectured that attackers can indefinitely block further requests to the Web server.
Version 7.1 of Fastream NetFIle FTP/Web Server was reported susceptible to this vulnerability. Other versions are also likely affected.
Fastream NetFile FTP/Web Server is reported susceptible to an HTTP HEAD request denial of service vulnerability.
This vulnerability allows remote attackers to create many simultaneous HTTP HEAD requests to the vulnerable server application. Once the attacker has created sufficient connections, further requests from legitimate users will reportedly be denied. Due to the failure of the application to close the previous connections, it is conjectured that attackers can indefinitely block further requests to the Web server.
Version 7.1 of Fastream NetFIle FTP/Web Server was reported susceptible to this vulnerability. Other versions are also likely affected.
Exploit / POC
Fastream NetFile FTP/Web Server HEAD Request Denial Of Service Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Fastream NetFile FTP/Web Server HEAD Request Denial Of Service Vulnerability
Solution:
It is reported that this vulnerability is addressed in Fastream NETFile FTP/Web Server 7.1.3 Professional. This is not confirmed. Customers are advised to contact the vendor in regards to obtaining and applying appropriate updates.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
It is reported that this vulnerability is addressed in Fastream NETFile FTP/Web Server 7.1.3 Professional. This is not confirmed. Customers are advised to contact the vendor in regards to obtaining and applying appropriate updates.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Fastream NetFile FTP/Web Server HEAD Request Denial Of Service Vulnerability
References:
References: