|
Crob FTP Server LIST Denial of Service Vulnerability
|
|
Secunia Advisory:
|
SA23365
|
|
|
Release Date:
|
2006-12-13
|
|
Last Update:
|
2006-12-18
|
|
Popularity:
|
6,214 views
|
|
|
Critical:
|
 Less critical
|
|
Impact:
|
DoS
|
|
Where:
|
From remote
|
|
Solution Status:
|
Unpatched
|
|
| Software: | Crob FTP Server 3.x
|
|
|
Subscribe:
|
Instant alerts on relevant vulnerabilities
|
|
| CVE reference: | CVE-2006-6558
|
|
Description: shinnai has discovered a vulnerability in Crob FTP Server, which can be exploited by malicious users to cause a DoS (Denial of Service).
The vulnerability is caused due to a boundary error within the handling of the LIST command. This can be exploited to crash the service via an overly long string (greater than 10,000 bytes) composed of "?A" characters passed as argument to the vulnerable command.
The vulnerability is confirmed in version 3.6.1 Build 263. Other versions may also be affected.
This vulnerability may be related to:
SA15585
Solution: Grant access to trusted users only.
Provided and/or discovered by: shinnai
Changelog: 2006-12-14: Added link to old advisory.
2006-12-18: Added CVE reference.
Original Advisory: http://milw0rm.com/exploits/2926
Other References: SA15585:
http://secunia.com/advisories/15585
|
|
|
Track this Secunia Advisory
|
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.
|
|
|
About this Secunia Advisory
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|