VID |
16137 |
Severity |
40 |
Port |
21 |
Protocol |
TCP |
Class |
FTP |
Detailed Description |
The remote host is running Serv-U File Server, an FTP server for Windows. According to its banner, the installed version of Serv-U is earlier than 9.1.0.0, and therefore affected by the following issues :
- A boundary error in the web administration interface when parsing session cookies can result in a stack buffer overflow.
- A boundary error in the TEA decoding algorithm can result in a stack buffer overflow when processing a long hexadecimal string.
* Note: This check solely relied on the version number of the remote FTP server to assess this vulnerability, so this might be a false positive.
* References: http://www.rangos.de/ServU-ADV.txt http://secunia.com/secunia_research/2009-46/ http://www.serv-u.com/releasenotes/
* Platforms Affected: Rhino Software, Inc., Serv-U FTP Server 9.1.0.0 prior Microsoft Windows Any version |
Recommendation |
Upgrade to latest version of Serv-U (9.1.0.0 or later), available from Serv-U Web site at http://www.serv-u.com/ |
Related URL |
CVE-2009-4006 (CVE) |
Related URL |
36895,37051 (SecurityFocus) |
Related URL |
(ISS) |
|