FileZilla FTP Server Multiple Remote Denial Of Service Vulnerabilities
BID:12865
Info
FileZilla FTP Server Multiple Remote Denial Of Service Vulnerabilities
| Bugtraq ID: | 12865 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2005-0850 CVE-2005-0851 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 22 2005 12:00AM |
| Updated: | Jul 12 2009 10:56AM |
| Credit: | These vulnerabilities were announced by the vendor. |
| Vulnerable: |
FileZilla FileZilla Server 0.7.1 FileZilla FileZilla Server 0.7 FileZilla FileZilla Server 0.9.5 FileZilla FileZilla Server 0.9.4e FileZilla FileZilla Server 0.9.4d FileZilla FileZilla Server 0.9.3 FileZilla FileZilla Server 0.9.2 FileZilla FileZilla Server 0.9.1b FileZilla FileZilla Server 0.9.0 FileZilla FileZilla Server 0.8.9 FileZilla FileZilla Server 0.8.8 FileZilla FileZilla Server 0.8.7 FileZilla FileZilla Server 0.8.6a FileZilla FileZilla Server 0.8.5 FileZilla FileZilla Server 0.8.4 FileZilla FileZilla Server 0.8.3 FileZilla FileZilla Server 0.8.2 FileZilla FileZilla Server 0.8.1 |
| Not Vulnerable: |
FileZilla FileZilla Server 0.9.6 |
Discussion
FileZilla FTP Server Multiple Remote Denial Of Service Vulnerabilities
The FileZilla FTP server is reported prone to multiple remote denial of service vulnerabilities. The following individual issues are reported:
It is reported that FileZilla fails to gracefully handle FTP requests that contain reserved MS-DOS device names. A remote authenticated attacker may exploit this vulnerability to deny service for legitimate users.
Finally, it is reported that the FileZilla FTP server may be influenced into entering an infinite loop. A remote authenticated attacker may exploit this vulnerability to deny service for legitimate users.
The FileZilla FTP server is reported prone to multiple remote denial of service vulnerabilities. The following individual issues are reported:
It is reported that FileZilla fails to gracefully handle FTP requests that contain reserved MS-DOS device names. A remote authenticated attacker may exploit this vulnerability to deny service for legitimate users.
Finally, it is reported that the FileZilla FTP server may be influenced into entering an infinite loop. A remote authenticated attacker may exploit this vulnerability to deny service for legitimate users.
Exploit / POC
FileZilla FTP Server Multiple Remote Denial Of Service Vulnerabilities
No exploits are required.
No exploits are required.
Solution / Fix
FileZilla FTP Server Multiple Remote Denial Of Service Vulnerabilities
Solution:
The vendor has released updates to address these vulnerabilities.
FileZilla FileZilla Server 0.9.5
FileZilla FileZilla Server 0.8.9
FileZilla FileZilla Server 0.8.7
FileZilla FileZilla Server 0.8.3
FileZilla FileZilla Server 0.9.4e
FileZilla FileZilla Server 0.8.8
FileZilla FileZilla Server 0.8.6a
FileZilla FileZilla Server 0.9.3
FileZilla FileZilla Server 0.8.2
FileZilla FileZilla Server 0.8.5
FileZilla FileZilla Server 0.8.4
FileZilla FileZilla Server 0.8.1
FileZilla FileZilla Server 0.9.0
FileZilla FileZilla Server 0.9.2
FileZilla FileZilla Server 0.9.4d
FileZilla FileZilla Server 0.9.1b
FileZilla FileZilla Server 0.7
FileZilla FileZilla Server 0.7.1
Solution:
The vendor has released updates to address these vulnerabilities.
FileZilla FileZilla Server 0.9.5
-
FileZilla FileZilla_Server_0_9_6.exe
http://prdownloads.sourceforge.net/filezilla/FileZilla_Server_0_9_6.ex e?download
FileZilla FileZilla Server 0.8.9
-
FileZilla FileZilla_Server_0_9_6.exe
http://prdownloads.sourceforge.net/filezilla/FileZilla_Server_0_9_6.ex e?download
FileZilla FileZilla Server 0.8.7
-
FileZilla FileZilla_Server_0_9_6.exe
http://prdownloads.sourceforge.net/filezilla/FileZilla_Server_0_9_6.ex e?download
FileZilla FileZilla Server 0.8.3
-
FileZilla FileZilla_Server_0_9_6.exe
http://prdownloads.sourceforge.net/filezilla/FileZilla_Server_0_9_6.ex e?download
FileZilla FileZilla Server 0.9.4e
-
FileZilla FileZilla_Server_0_9_6.exe
http://prdownloads.sourceforge.net/filezilla/FileZilla_Server_0_9_6.ex e?download
FileZilla FileZilla Server 0.8.8
-
FileZilla FileZilla_Server_0_9_6.exe
http://prdownloads.sourceforge.net/filezilla/FileZilla_Server_0_9_6.ex e?download
FileZilla FileZilla Server 0.8.6a
-
FileZilla FileZilla_Server_0_9_6.exe
http://prdownloads.sourceforge.net/filezilla/FileZilla_Server_0_9_6.ex e?download
FileZilla FileZilla Server 0.9.3
-
FileZilla FileZilla_Server_0_9_6.exe
http://prdownloads.sourceforge.net/filezilla/FileZilla_Server_0_9_6.ex e?download
FileZilla FileZilla Server 0.8.2
-
FileZilla FileZilla_Server_0_9_6.exe
http://prdownloads.sourceforge.net/filezilla/FileZilla_Server_0_9_6.ex e?download
FileZilla FileZilla Server 0.8.5
-
FileZilla FileZilla_Server_0_9_6.exe
http://prdownloads.sourceforge.net/filezilla/FileZilla_Server_0_9_6.ex e?download
FileZilla FileZilla Server 0.8.4
-
FileZilla FileZilla_Server_0_9_6.exe
http://prdownloads.sourceforge.net/filezilla/FileZilla_Server_0_9_6.ex e?download
FileZilla FileZilla Server 0.8.1
-
FileZilla FileZilla_Server_0_9_6.exe
http://prdownloads.sourceforge.net/filezilla/FileZilla_Server_0_9_6.ex e?download
FileZilla FileZilla Server 0.9.0
-
FileZilla FileZilla_Server_0_9_6.exe
http://prdownloads.sourceforge.net/filezilla/FileZilla_Server_0_9_6.ex e?download
FileZilla FileZilla Server 0.9.2
-
FileZilla FileZilla_Server_0_9_6.exe
http://prdownloads.sourceforge.net/filezilla/FileZilla_Server_0_9_6.ex e?download
FileZilla FileZilla Server 0.9.4d
-
FileZilla FileZilla_Server_0_9_6.exe
http://prdownloads.sourceforge.net/filezilla/FileZilla_Server_0_9_6.ex e?download
FileZilla FileZilla Server 0.9.1b
-
FileZilla FileZilla_Server_0_9_6.exe
http://prdownloads.sourceforge.net/filezilla/FileZilla_Server_0_9_6.ex e?download
FileZilla FileZilla Server 0.7
-
FileZilla FileZilla_Server_0_9_6.exe
http://prdownloads.sourceforge.net/filezilla/FileZilla_Server_0_9_6.ex e?download
FileZilla FileZilla Server 0.7.1
-
FileZilla FileZilla_Server_0_9_6.exe
http://prdownloads.sourceforge.net/filezilla/FileZilla_Server_0_9_6.ex e?download
References
FileZilla FTP Server Multiple Remote Denial Of Service Vulnerabilities
References:
References:
- FileZilla Homepage (FileZilla )
- Release Name: 0.9.6 (FileZilla)