Serv-U Denial of Service and Security Bypass Vulnerabilities
BID:42523
Info
Serv-U Denial of Service and Security Bypass Vulnerabilities
| Bugtraq ID: | 42523 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 16 2010 12:00AM |
| Updated: | Aug 16 2010 12:00AM |
| Credit: | Reported by the vendor. |
| Vulnerable: |
Rhino Software Serv-U 10.1.0.1 |
| Not Vulnerable: |
Rhino Software Serv-U 10.2.0.0 |
Discussion
Serv-U Denial of Service and Security Bypass Vulnerabilities
Serv-U is prone to denial-of-service and security-bypass vulnerabilities.
Exploiting these issues can allow attackers to create directories without having sufficient permissions, or crash the affected application, resulting in denial-of-service conditions.
Versions prior to Serv-U 10.2.0.0 are vulnerable.
Serv-U is prone to denial-of-service and security-bypass vulnerabilities.
Exploiting these issues can allow attackers to create directories without having sufficient permissions, or crash the affected application, resulting in denial-of-service conditions.
Versions prior to Serv-U 10.2.0.0 are vulnerable.
Exploit / POC
Serv-U Denial of Service and Security Bypass Vulnerabilities
An attacker can use standard tools to exploit these issues. To exploit the denial-of-service issues the attacker needs to entice a user to process a specially crafted URI.
An attacker can use standard tools to exploit these issues. To exploit the denial-of-service issues the attacker needs to entice a user to process a specially crafted URI.
Solution / Fix
Serv-U Denial of Service and Security Bypass Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Serv-U Denial of Service and Security Bypass Vulnerabilities
References:
References:
- Serv-U Release Notes (Serv-U)
- Vendor Homepage (Serv-U)