VID |
16135 |
Severity |
30 |
Port |
21 |
Protocol |
TCP |
Class |
FTP |
Detailed Description |
The installed version of Serv-U 7.x is earlier than 7.4.0.0, and is therefore affected by a denial of service vulnerability. By using a specially crafted command such as XCRC, STOU, DSIZ, AVBL, RNTO, or RMDA, it may be possible for an authenticated attacker to render the FTP server temporarily unresponsive.
* Note: This check solely relied on the version number of the remote FTP server to assess this vulnerability, so this might be a false positive.
* References: http://www.serv-u.com/releasenotes/
* Platforms Affected: Rhino Software, Inc., Serv-U FTP Server 7.4.0.0 and prior Microsoft Windows Any version |
Recommendation |
Upgrade to latest version of Serv-U (7.4.0.0 or later), available from Serv-U Web site at http://www.serv-u.com/ |
Related URL |
(CVE) |
Related URL |
33180 (SecurityFocus) |
Related URL |
(ISS) |
|