Korean
<< Back
VID 16151
Severity 30
Port 21, ...
Protocol TCP
Class FTP
Detailed Description The remote host is using ProFTPD, a free FTP server for Unix and Linux.
According to its banner, the version of ProFTPD installed on the remote host is earlier than 1.3.2rc3 and is affected by a Denial of Service vulnerability via an ABOR command during a data transfer.

* Note: This check solely relied on the banner of the remote ProFTPD server to assess this vulnerability, so this might be a false positive.

* References:
http://bugs.proftpd.org/show_bug.cgi?id=3131
http://www.debian.org/security/2011/dsa-2191

* Platforms Affected:
ProFTPD prior to 1.3.2rc3
Any operating system Any version
Recommendation Upgrade to the latest version of ProFTPD (1.3.2rc3 or later), available from the ProFTPD web site at http://www.proftpd.org/
Related URL CVE-2008-7265 (CVE)
Related URL 84378 (SecurityFocus)
Related URL (ISS)