Korean
<< Back
VID 16146
Severity 20
Port 21
Protocol TCP
Class FTP
Detailed Description According to its banner, the installed version of Serv-U is earlier than 14.0.2.0 and is, therefore, potentially affected by a denial of service vulnerability. RhinoSoft Serv-U FTP is an FTP server for Microsoft Windows operating systems. A remote attacker could cause denial of service conditions by continually sending SSL renegotiation requests to the application.

* Note: This check solely relied on the version number of the remote FTP server to assess this vulnerability, so this might be a false positive.

* References:
http://www.serv-u.com/releasenotes/

* Platforms Affected:
Rhino Software, Inc., Serv-U FTP Server before 14.0.2.0
Microsoft Windows Any version
Recommendation Upgrade to latest version of Serv-U (14.0.2.0 or later), available from Serv-U Web site at http://www.serv-u.com/
Related URL (CVE)
Related URL 61139 (SecurityFocus)
Related URL (ISS)