Etype EServ Passive Mode Denial of Service Vulnerability
BID:3983
Info
Etype EServ Passive Mode Denial of Service Vulnerability
| Bugtraq ID: | 3983 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2002-0221 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 29 2002 12:00AM |
| Updated: | Jul 11 2009 09:56AM |
| Credit: | Discovered and posted to Bugtraq by Arne Vidstrom <[email protected]>. |
| Vulnerable: |
Etype Eserv 2.97 |
| Not Vulnerable: |
Etype Eserv 2.98 |
Discussion
Etype EServ Passive Mode Denial of Service Vulnerability
EType EServ is a combination Mail, News, Web, FTP and Proxy Server for Microsoft Windows 9x/NT/2000 systems.
There is an exploitable denial of service vulnerability in EServ FTP server. It is possible to cause the server to stop accepting passive mode commands. This is accomplished by sending a large number of 'PASV' requests.
In the event that the affected service crashes, it will have to be restarted in order to regain normal functionality.
This vulnerability does not require any user authentication to exploit.
EType EServ is a combination Mail, News, Web, FTP and Proxy Server for Microsoft Windows 9x/NT/2000 systems.
There is an exploitable denial of service vulnerability in EServ FTP server. It is possible to cause the server to stop accepting passive mode commands. This is accomplished by sending a large number of 'PASV' requests.
In the event that the affected service crashes, it will have to be restarted in order to regain normal functionality.
This vulnerability does not require any user authentication to exploit.
Exploit / POC
Etype EServ Passive Mode Denial of Service Vulnerability
No exploit code is required.
No exploit code is required.
Solution / Fix
Etype EServ Passive Mode Denial of Service Vulnerability
Solution:
Etype has addressed this issue in EServ FTP 2.98:
Etype Eserv 2.97
Solution:
Etype has addressed this issue in EServ FTP 2.98:
Etype Eserv 2.97
-
Etype Eserv3123
ftp://ftp.eserv.ru/pub/beta/2.98/Eserv3123.zip