AppleShare IP FTP Server RMD Command Denial Of Service Vulnerability
BID:9159
Info
AppleShare IP FTP Server RMD Command Denial Of Service Vulnerability
| Bugtraq ID: | 9159 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 05 2003 12:00AM |
| Updated: | Dec 05 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to Spencer Clark <[email protected]>. |
| Vulnerable: |
Apple AppleShare IP 6.3.1 Apple AppleShare IP 6.3 Apple AppleShare IP 6.2 Apple AppleShare IP 6.1 Apple AppleShare IP 5.0.3 Apple AppleShare IP 5.0.2 Apple AppleShare IP 5.0.1 Apple AppleShare IP 5.0 |
| Not Vulnerable: |
Apple AppleShare IP 6.3.3 Apple AppleShare IP 6.3.2 |
Discussion
AppleShare IP FTP Server RMD Command Denial Of Service Vulnerability
The AppleShare IP FTP server has been reported prone to a denial of service vulnerability. The issue presents itself if a remote attacker invokes the 'RMD' command in a specific manner when logged into an AppleShare IP FTP server. This action will have the reported affect of causing the system that is hosting the AppleShare software to lock, preventing any interaction and thereby effectively deny service to legitimate system users.
The AppleShare IP FTP server has been reported prone to a denial of service vulnerability. The issue presents itself if a remote attacker invokes the 'RMD' command in a specific manner when logged into an AppleShare IP FTP server. This action will have the reported affect of causing the system that is hosting the AppleShare software to lock, preventing any interaction and thereby effectively deny service to legitimate system users.
Exploit / POC
AppleShare IP FTP Server RMD Command Denial Of Service Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
AppleShare IP FTP Server RMD Command Denial Of Service Vulnerability
Solution:
It has been reported that versions of AppleShare IP release after version 6.3.1 are not prone to this issue. Affected users are advised to contact the vendor for upgrade information.
Solution:
It has been reported that versions of AppleShare IP release after version 6.3.1 are not prone to this issue. Affected users are advised to contact the vendor for upgrade information.
References
AppleShare IP FTP Server RMD Command Denial Of Service Vulnerability
References:
References:
- AppleShare IP Product Home Page (Apple)
- Problem with Appleshare IP FTP server (Spencer Clark
)