FileZilla Server Null Pointer Dereference Multiple Denial of Service Vulnerabilities
BID:21549
Info
FileZilla Server Null Pointer Dereference Multiple Denial of Service Vulnerabilities
| Bugtraq ID: | 21549 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 11 2006 12:00AM |
| Updated: | Dec 11 2006 12:00AM |
| Credit: | shinnai is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
FileZilla FileZilla Server 0.9.21 FileZilla FileZilla Server 0.9.19 FileZilla FileZilla Server 0.9.17 FileZilla FileZilla Server 0.9.16 b FileZilla FileZilla Server 0.9.9 FileZilla FileZilla Server 0.9.8 c FileZilla FileZilla Server 0.9.8 b FileZilla FileZilla Server 0.9.8 a FileZilla FileZilla Server 0.9.8 FileZilla FileZilla Server 0.7.1 FileZilla FileZilla Server 0.7 FileZilla FileZilla Server 0.9.6 FileZilla FileZilla Server 0.9.5 FileZilla FileZilla Server 0.9.4e FileZilla FileZilla Server 0.9.4d FileZilla FileZilla Server 0.9.3 FileZilla FileZilla Server 0.9.20 FileZilla FileZilla Server 0.9.2 FileZilla FileZilla Server 0.9.1b FileZilla FileZilla Server 0.9.0 FileZilla FileZilla Server 0.8.9 FileZilla FileZilla Server 0.8.8 FileZilla FileZilla Server 0.8.7 FileZilla FileZilla Server 0.8.6a FileZilla FileZilla Server 0.8.5 FileZilla FileZilla Server 0.8.4 FileZilla FileZilla Server 0.8.3 FileZilla FileZilla Server 0.8.2 FileZilla FileZilla Server 0.8.1 |
| Not Vulnerable: |
FileZilla FileZilla Server 0.9.22 |
Discussion
FileZilla Server Null Pointer Dereference Multiple Denial of Service Vulnerabilities
FileZilla server is prone to multiple denial-of-service vulnerabilities because it fails to handle exceptional conditions.
An attacker can exploit these issues to crash the affected application, denying service to legitimate users.
Versions prior to 0.9.22 are vulnerable to these issues.
FileZilla server is prone to multiple denial-of-service vulnerabilities because it fails to handle exceptional conditions.
An attacker can exploit these issues to crash the affected application, denying service to legitimate users.
Versions prior to 0.9.22 are vulnerable to these issues.
Exploit / POC
FileZilla Server Null Pointer Dereference Multiple Denial of Service Vulnerabilities
An attacker can use standard network utilities to exploit these issues.
An attacker can use standard network utilities to exploit these issues.
Solution / Fix
FileZilla Server Null Pointer Dereference Multiple Denial of Service Vulnerabilities
Solution:
The vendor has released an update to address these issues. Please see the references for more information.
Solution:
The vendor has released an update to address these issues. Please see the references for more information.
References
FileZilla Server Null Pointer Dereference Multiple Denial of Service Vulnerabilities
References:
References:
- FileZilla Server Change Log 0.9.22 (FileZilla )
- Vendor Home Page (FileZilla)