Korean
<< Back
VID 16153
Severity 30
Port 21, ...
Protocol TCP
Class FTP
Detailed Description The remote host is using ProFTPD, a free FTP server for Unix and Linux.
According to its banner, the version of ProFTPD installed on the remote host is earlier than 1.3.4rc2 and is affected by a Denial of Service vulnerability in the mod_sftp module.

* Note: This check solely relied on the banner of the remote ProFTPD server to assess this vulnerability, so this might be a false positive.

* References:
http://bugs.proftpd.org/show_bug.cgi?id=3586

* Platforms Affected:
ProFTPD prior to 1.3.4rc2
Any operating system Any version
Recommendation Upgrade to the latest version of ProFTPD (1.3.4rc2 or later), available from the ProFTPD web site at http://www.proftpd.org/
Related URL CVE-2011-1137 (CVE)
Related URL 46183 (SecurityFocus)
Related URL (ISS)