FileZilla FTP Server Multiple DoS
High Nessus Plugin ID 17593
SynopsisThe remote FTP server has multiple denial of service vulnerabilities.
DescriptionThe remote host is running a version of FileZilla server with the following denial of service vulnerabilities :
- Requesting a file containing the reserved name of a DOS device (e.g. CON, NUL, COM1, etc.) can cause the server to freeze.
- Downloading a file or directory listing with MODE Z enabled (zlib compression) can cause an infinite loop.
SolutionUpgrade to FileZilla Server 0.9.6 or later.