CesarFTP Remote CWD Denial of Service Vulnerability
BID:7950
Info
CesarFTP Remote CWD Denial of Service Vulnerability
| Bugtraq ID: | 7950 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 30 2003 12:00AM |
| Updated: | Mar 30 2003 12:00AM |
| Credit: | The discovery of this vulnerability has been credited to dr_insane. |
| Vulnerable: |
ACLogic CesarFTP 0.99 g |
| Not Vulnerable: | |
Discussion
CesarFTP Remote CWD Denial of Service Vulnerability
A vulnerability has been reported for CesarFTP. Reportedly, an attacker may crash a target server by supplying excessive data as the argument to the 'CWD' command. This may result in the server hanging, effectively denying service to other legitimate FTP users.
A vulnerability has been reported for CesarFTP. Reportedly, an attacker may crash a target server by supplying excessive data as the argument to the 'CWD' command. This may result in the server hanging, effectively denying service to other legitimate FTP users.
Exploit / POC
CesarFTP Remote CWD Denial of Service Vulnerability
No exploit is required.
The following proof of concept has been supplied:
No exploit is required.
The following proof of concept has been supplied:
Solution / Fix
CesarFTP Remote CWD Denial of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.