Rumpus FTP Server Stack Overflow DoS Vulnerability

BID:2864

Info

Rumpus FTP Server Stack Overflow DoS Vulnerability

Bugtraq ID: 2864
Class: Boundary Condition Error
CVE:
Remote: Yes
Local: No
Published: Jun 12 2001 12:00AM
Updated: Jun 12 2001 12:00AM
Credit: Jass Seljamaa <[email protected]> published this vulnerability on June 12th, 2001.
Vulnerable: Maxum Rumpus FTP Server 2.0.3 dev
Maxum Rumpus FTP Server 1.3.5
Maxum Rumpus FTP Server 1.3.4
Maxum Rumpus FTP Server 1.3.2
Not Vulnerable: Maxum Rumpus FTP Server 1.3.6

Discussion

Rumpus FTP Server Stack Overflow DoS Vulnerability

Rumpus FTP Server is an implementation for MacOS which allows file-sharing across TCP/IP connections.

Rumpus FTP is prone to a denial of service. An ftp user can engage the attack by making a directory with an unusual number of sub-folders. This forces the software to quit, as it is unable to handle the creation of so many directories at one time. The FTP server must be rebooted to regain normal functionality.

It is required that a user be logged in to carry out this attack. It may be possible for remote users to exploit this vulnerability, but authentication is required and anonymous ftp access does not grant users the privileges neccesary to create directories.

Solution / Fix

Rumpus FTP Server Stack Overflow DoS Vulnerability

Solution:
Rumpus FTP Server 1.3.6 is an updated version which addresses this issue. The vendor freely offers upgrades to users affected by this issue.

References

Rumpus FTP Server Stack Overflow DoS Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report