Korean
<< Back
VID 16136
Severity 30
Port 21
Protocol TCP
Class FTP
Detailed Description The installed version of Serv-U is earlier than 8.0.0.1 and thus reportedly affected by the following issues :

- A directory traversal vulnerability enables an authenticated remote attacker to create directories outside his or her home directory. (CVE-2009-1031)

- An authenticated remote attacker can cause the FTP service to become saturated for a long period of time using a long series of 'SMNT' commands without an argument. During this time, new connections would not be allowed. (CVE-2009-0967)


* Note: This check solely relied on the version number of the remote FTP server to assess this vulnerability, so this might be a false positive.

* References:
http://www.serv-u.com/releasenotes/

* Platforms Affected:
Rhino Software, Inc., Serv-U FTP Server 8.0.0.1 and prior
Microsoft Windows Any version
Recommendation Upgrade to latest version of Serv-U (8.0.0.1 or later), available from Serv-U Web site at http://www.serv-u.com/
Related URL CVE-2009-0967,CVE-2009-1031 (CVE)
Related URL 34125,34127 (SecurityFocus)
Related URL (ISS)