Korean
<< Back
VID 16132
Severity 30
Port 21
Protocol TCP
Class FTP
Detailed Description The Serv-U FTP Server, according to its banner, has a server crash vulnerability via the 'SITE SET' command. RhinoSoft Serv-U FTP is an FTP server for Microsoft Windows operating systems. Serv-U FTP versions 9.0.0.1 prior are vulnerable to crash the remote FTP server by sending a specially crafted 'SITE SET TRANSFERPROGRESS ON' command. An unprivileged user may be able to view all drives and virtual paths for drive '\'.

* Note: This check solely relied on the version number of the remote FTP server to assess this vulnerability, so this might be a false positive.

* References:
http://www.serv-u.com/releasenotes/

* Platforms Affected:
Rhino Software, Inc., Serv-U FTP Server 9.0.0.1 prior
Microsoft Windows Any version
Recommendation Upgrade to latest version of Serv-U (9.0.0.1 or later), available from Serv-U Web site at http://www.serv-u.com/
Related URL CVE-2009-3655 (CVE)
Related URL 36585 (SecurityFocus)
Related URL (ISS)