wzdftpd USER Command Remote Denial of Service Vulnerability
BID:25967
Info
wzdftpd USER Command Remote Denial of Service Vulnerability
| Bugtraq ID: | 25967 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2007-5300 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 08 2007 12:00AM |
| Updated: | Jan 07 2008 11:29PM |
| Credit: | k1tk4t is credited with the discovery of this vulnerability. |
| Vulnerable: |
wzdftpd wzdftpd 0.8 wzdftpd wzdftpd 0.7.3 wzdftpd wzdftpd 0.7.2 wzdftpd wzdftpd 0.7.1 wzdftpd wzdftpd 0.5.4 wzdftpd wzdftpd 0.5.2 wzdftpd wzdftpd 0.1 rc5 wzdftpd wzdftpd 0.1 rc4 wzdftpd wzdftpd 0.1 cvs-20030613 wzdftpd wzdftpd 0.1 wzdftpd wzdftpd 1rc5 Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 |
| Not Vulnerable: | |
Discussion
wzdftpd USER Command Remote Denial of Service Vulnerability
The 'wzdftpd' application is prone to a remote denial-of-service vulnerability because it fails to handle exceptional conditions.
Successfully exploiting this issue would cause the affected application to crash, denying service to legitimate users. Arbitrary code execution may also be possible, but this has not been confirmed.
This issue affects wzdftpd 0.8.0 and prior versions.
The 'wzdftpd' application is prone to a remote denial-of-service vulnerability because it fails to handle exceptional conditions.
Successfully exploiting this issue would cause the affected application to crash, denying service to legitimate users. Arbitrary code execution may also be possible, but this has not been confirmed.
This issue affects wzdftpd 0.8.0 and prior versions.
Exploit / POC
wzdftpd USER Command Remote Denial of Service Vulnerability
Attackers can exploit this issue by using readily available network tools and/or FTP clients.
The following exploit is available:
Attackers can exploit this issue by using readily available network tools and/or FTP clients.
The following exploit is available:
Solution / Fix
wzdftpd USER Command Remote Denial of Service Vulnerability
Solution:
Reports indicate that wzdftpd 0.8.1 is not vulnerable to this issue; Symantec has not confirmed this.
Please see the referenced advisories for more information.
Solution:
Reports indicate that wzdftpd 0.8.1 is not vulnerable to this issue; Symantec has not confirmed this.
Please see the referenced advisories for more information.