SmallFTPD Login Denial of Service Vulnerability
BID:7474
Info
SmallFTPD Login Denial of Service Vulnerability
| Bugtraq ID: | 7474 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 30 2003 12:00AM |
| Updated: | Apr 30 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to "aT4r InsaN3" <[email protected]>. |
| Vulnerable: |
smallftpd smallftpd 0.99 |
| Not Vulnerable: |
smallftpd smallftpd 1.0.2 |
Discussion
SmallFTPD Login Denial of Service Vulnerability
smallftpd has been reported prone to a DoS condition when handling malicious login credentials.
It has been reported that if the smallftpd receives malformed login credentials during the smallftpd authentication procedure the server will crash.
smallftpd has been reported prone to a DoS condition when handling malicious login credentials.
It has been reported that if the smallftpd receives malformed login credentials during the smallftpd authentication procedure the server will crash.
Exploit / POC
SmallFTPD Login Denial of Service Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
SmallFTPD Login Denial of Service Vulnerability
Solution:
This vulnerability has been reportedly addressed in the current version of the software:
smallftpd smallftpd 0.99
Solution:
This vulnerability has been reportedly addressed in the current version of the software:
smallftpd smallftpd 0.99
-
smallftpd smallftpd version 1.0.2
http://smallftpd.free.fr/#last
References
SmallFTPD Login Denial of Service Vulnerability
References:
References:
- Smallftpd Homepage (Smallftpd)
- smallftpd's version 1.0.2 Directory Transversal Vulnerability ("aT4r InsaN3"
)