Cerberus FTP Server 'ALLO' Command Denial Of Service Vulnerability
BID:36134
Info
Cerberus FTP Server 'ALLO' Command Denial Of Service Vulnerability
| Bugtraq ID: | 36134 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 25 2009 12:00AM |
| Updated: | Aug 26 2009 09:22PM |
| Credit: | Francis Provencher from Protek Research Labs |
| Vulnerable: |
Cerberus FTP Server 3.0.1 |
| Not Vulnerable: |
Cerberus FTP Server 3.0.2 |
Discussion
Cerberus FTP Server 'ALLO' Command Denial Of Service Vulnerability
Cerberus FTP Server is prone to a denial-of-service vulnerability.
A successful exploit may allow attackers to halt the server process, resulting in a denial-of-service condition.
Versions prior to Cerberus FTP Server 3.0.2 are vulnerable.
Cerberus FTP Server is prone to a denial-of-service vulnerability.
A successful exploit may allow attackers to halt the server process, resulting in a denial-of-service condition.
Versions prior to Cerberus FTP Server 3.0.2 are vulnerable.
Exploit / POC
Cerberus FTP Server 'ALLO' Command Denial Of Service Vulnerability
Attackers may use readily available tools to exploit this issue.
The following exploit is available:
Attackers may use readily available tools to exploit this issue.
The following exploit is available:
Solution / Fix
Cerberus FTP Server 'ALLO' Command Denial Of Service Vulnerability
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
Cerberus FTP Server 'ALLO' Command Denial Of Service Vulnerability
References:
References:
- Cerberus FTP Server Homepage (Cerberus)
- Cerebrus FTP server 3.0 crash bug (strace)
- Cerberus FTP Server- Release Notes (Cerberus)