Multiple FTP Vendor 'GET' Denial of Service Vulnerability
BID:2698
Info
Multiple FTP Vendor 'GET' Denial of Service Vulnerability
| Bugtraq ID: | 2698 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 17 2001 12:00AM |
| Updated: | Feb 17 2001 12:00AM |
| Credit: | Posted to Bugtraq by Tom Tom <[email protected]> on May 6, 2001 and discovered by t-Omicr0n <[email protected]> on February 17, 2001. |
| Vulnerable: |
Jgaa WarFTPd 1.71 Gene6 BPFTP Server 2.0 Cat Soft Serv-U 2.5 |
| Not Vulnerable: | |
Discussion
Multiple FTP Vendor 'GET' Denial of Service Vulnerability
It is possible for a remote user to cause a denial of service on a host running Serv-U FTP Server, G6 FTP Server or WarFTPd Server. Repeatedly submitting an 'a:/' GET or RETR request, appended with arbitrary data, will cause the CPU usage to spike to 100%.
It is possible for a remote user to cause a denial of service on a host running Serv-U FTP Server, G6 FTP Server or WarFTPd Server. Repeatedly submitting an 'a:/' GET or RETR request, appended with arbitrary data, will cause the CPU usage to spike to 100%.
Exploit / POC
Multiple FTP Vendor 'GET' Denial of Service Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Multiple FTP Vendor 'GET' Denial of Service Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Multiple FTP Vendor 'GET' Denial of Service Vulnerability
References:
References:
- BPFTP Server Homepage (Gene6)
- FTP Serv-U Product Homepage (Cat Soft)
- WarFTP Homepage (Jgaa)