| VID |
16079 |
| Severity |
30 |
| Port |
21 |
| Protocol |
TCP |
| Class |
FTP |
| Detailed Description |
The Serv-U FTP Server, according to its banner, has a denial of service vulnerability via the "STOU" command. RhinoSoft Serv-U FTP is an FTP server for Microsoft Windows operating systems. Serv-U FTP versions 5.2.0.1 prior are vulnerable to a denial of service attack, due to insufficient validation of arguments passed via the "STOU" command. This can be exploited to crash the service by passing a reserved DOS device name as argument.
Examples: STOU COM1 STOU LPT1 STOU PRN STOU AUX
* Note: This check solely relied on the version number of the remote FTP server to assess this vulnerability, so this might be a false positive.
* References: http://secunia.com/advisories/12507/
* Platforms Affected: Rhino Software, Inc., Serv-U FTP Server 5.2 and prior Microsoft Windows Any version |
| Recommendation |
Upgrade to latest version of Serv-U (5.2.0.1 or later), available from Serv-U Web site at http://www.serv-u.com/ |
| Related URL |
CVE-2004-1675 (CVE) |
| Related URL |
11155 (SecurityFocus) |
| Related URL |
17329 (ISS) |
|