icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons_061

Serv-U < 9.0.0.1 Multiple Vulnerabilities

Medium

Synopsis

The remote host is vulnerable to multiple attack vectors.

Description

The remote host is running Serv-U File Server, an FTP server for Windows. The installed version is earlier than 9.0.0.1. Such versions are potentially affected by multiple issues :

- A remote denial-of-service when processing specially crafted 'SITE SET TRANSFERPROGRESS ON' commands. An authenticated attacker can exploit this flaw to cause a denial-of-service when 'SITE SET' commands are enabled on the server.

- An unprivileged user may be able to view all drives and virtual paths for drive '\\'.

Solution

Upgrade to Serv-U version 9.0.0.1 or later.