TYPSoft FTP 'RETR' and 'STOR' Denial of Service Vulnerability
BID:3409
Info
TYPSoft FTP 'RETR' and 'STOR' Denial of Service Vulnerability
| Bugtraq ID: | 3409 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2001-1156 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 09 2001 12:00AM |
| Updated: | Jul 11 2009 09:06AM |
| Credit: | Discovered and posted to Bugtraq by J. Wagner <[email protected]> on Oct 9, 2001. |
| Vulnerable: |
TYPSoft TYPSoft FTP Server 0.95 |
| Not Vulnerable: |
TYPSoft TYPSoft FTP Server 0.96 |
Discussion
TYPSoft FTP 'RETR' and 'STOR' Denial of Service Vulnerability
TYPSoft FTP server is subject to denial of service attacks.
A malicious argument string submitted using either 'RETR' or 'STOR' commands to a host running TYPSoft FTP server, will result in the service terminating.
A restart of the server is required in order to gain normal functionality.
TYPSoft FTP server is subject to denial of service attacks.
A malicious argument string submitted using either 'RETR' or 'STOR' commands to a host running TYPSoft FTP server, will result in the service terminating.
A restart of the server is required in order to gain normal functionality.
Exploit / POC
TYPSoft FTP 'RETR' and 'STOR' Denial of Service Vulnerability
J. Wagner <[email protected]> has provided the following exploit:
J. Wagner <[email protected]> has provided the following exploit:
Solution / Fix
TYPSoft FTP 'RETR' and 'STOR' Denial of Service Vulnerability
Solution:
This issue has been addressed in TYPSoft FTP Server 0.96 and up. Currently, the latest version is 0.97.5:
TYPSoft TYPSoft FTP Server 0.95
Solution:
This issue has been addressed in TYPSoft FTP Server 0.96 and up. Currently, the latest version is 0.97.5:
TYPSoft TYPSoft FTP Server 0.95
-
TYPSoft ftpserven
http://www.typsoft.com/files/ftpserven.exe
References
TYPSoft FTP 'RETR' and 'STOR' Denial of Service Vulnerability
References:
References:
- TYPSoft FTP Server Homepage (TYPSoft)