Serv-U 7.x < 7.4.0.0 Multiple Command Remote DoS

Medium Nessus Plugin ID 35328

Synopsis

The remote FTP server is affected by a denial of service vulnerability.

Description

The installed version of Serv-U 7.x is earlier than 7.4.0.0, and is therefore affected by a denial of service vulnerability. By using a specially crafted command such as XCRC, STOU, DSIZ, AVBL, RNTO, or RMDA, it may be possible for an authenticated attacker to render the FTP server temporarily unresponsive.

Solution

Upgrade to Serv-U version 7.4.0.0 or later.

See Also

https://support.solarwinds.com/Success_Center/Serv-U_Managed_File_Transfer_Serv-U_FTP_Server/Serv-U_Documentation/release_notes

Plugin Details

Severity: Medium

ID: 35328

File Name: servu_7_4_0_0.nasl

Version: 1.12

Type: remote

Family: FTP

Published: 2009/01/09

Updated: 2018/11/15

Dependencies: 48434

Risk Information

Risk Factor: Medium

CVSS v2.0

Base Score: 4

Temporal Score: 3

Vector: CVSS2#AV:N/AC:L/Au:S/C:N/I:N/A:P

Temporal Vector: CVSS2#E:U/RL:OF/RC:C

Vulnerability Information

CPE: cpe:/a:serv-u:serv-u

Required KB Items: ftp/servu

Exploit Available: false

Exploit Ease: No known exploits are available

Reference Information

BID: 33180

Secunia: 33411