GLSA-200403-08 : oftpd DoS vulnerability

This script is Copyright (C) 2004-2014 Tenable Network Security, Inc.


Synopsis :

The remote Gentoo host is missing one or more security-related
patches.

Description :

The remote host is affected by the vulnerability described in GLSA-200403-08
(oftpd DoS vulnerability)

Issuing a port command with a number higher than 255 causes the server
to crash. The port command may be issued before any authentication
takes place, meaning the attacker does not need to know a valid
username and password in order to exploit this vulnerability.

Impact :

This exploit causes a denial of service.

Workaround :

While a workaround is not currently known for this issue, all users are
advised to upgrade to the latest version of the affected package.

See also :

http://www.time-travellers.org/oftpd/
http://www.time-travellers.org/oftpd/oftpd-dos.html
http://www.gentoo.org/security/en/glsa/glsa-200403-08.xml

Solution :

All users should upgrade to the current version of the affected
package:
# emerge sync
# emerge -pv '>=net-ftp/oftpd-0.3.7'
# emerge '>=net-ftp/oftpd-0.3.7'

Risk factor :

Medium / CVSS Base Score : 5.0
(CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P)

Family: Gentoo Local Security Checks

Nessus Plugin ID: 14459 (gentoo_GLSA-200403-08.nasl)

Bugtraq ID:

CVE ID: CVE-2004-0376