Rumpus FTP Server Stack Overflow DoS Vulnerability
BID:2864
Info
Rumpus FTP Server Stack Overflow DoS Vulnerability
| Bugtraq ID: | 2864 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 12 2001 12:00AM |
| Updated: | Jun 12 2001 12:00AM |
| Credit: | Jass Seljamaa <[email protected]> published this vulnerability on June 12th, 2001. |
| Vulnerable: |
Maxum Rumpus FTP Server 2.0.3 dev Maxum Rumpus FTP Server 1.3.5 Maxum Rumpus FTP Server 1.3.4 Maxum Rumpus FTP Server 1.3.2 |
| Not Vulnerable: |
Maxum Rumpus FTP Server 1.3.6 |
Discussion
Rumpus FTP Server Stack Overflow DoS Vulnerability
Rumpus FTP Server is an implementation for MacOS which allows file-sharing across TCP/IP connections.
Rumpus FTP is prone to a denial of service. An ftp user can engage the attack by making a directory with an unusual number of sub-folders. This forces the software to quit, as it is unable to handle the creation of so many directories at one time. The FTP server must be rebooted to regain normal functionality.
It is required that a user be logged in to carry out this attack. It may be possible for remote users to exploit this vulnerability, but authentication is required and anonymous ftp access does not grant users the privileges neccesary to create directories.
Rumpus FTP Server is an implementation for MacOS which allows file-sharing across TCP/IP connections.
Rumpus FTP is prone to a denial of service. An ftp user can engage the attack by making a directory with an unusual number of sub-folders. This forces the software to quit, as it is unable to handle the creation of so many directories at one time. The FTP server must be rebooted to regain normal functionality.
It is required that a user be logged in to carry out this attack. It may be possible for remote users to exploit this vulnerability, but authentication is required and anonymous ftp access does not grant users the privileges neccesary to create directories.
Solution / Fix
Rumpus FTP Server Stack Overflow DoS Vulnerability
Solution:
Rumpus FTP Server 1.3.6 is an updated version which addresses this issue. The vendor freely offers upgrades to users affected by this issue.
Solution:
Rumpus FTP Server 1.3.6 is an updated version which addresses this issue. The vendor freely offers upgrades to users affected by this issue.
References
Rumpus FTP Server Stack Overflow DoS Vulnerability
References:
References:
- Rumpus FTP Server Product Page (Maxum)