FileZilla FTP Server Multiple DoS
High Nessus Plugin ID 17593
SynopsisThe remote FTP server has multiple denial of service vulnerabilities.
DescriptionThe remote host is running a version of FileZilla server with the
following denial of service vulnerabilities :
- Requesting a file containing the reserved name of a DOS
device (e.g. CON, NUL, COM1, etc.) can cause the
server to freeze.
- Downloading a file or directory listing with MODE Z
enabled (zlib compression) can cause an infinite loop.
SolutionUpgrade to FileZilla Server 0.9.6 or later.