Serv-U 7.x < 7.4.0.0 Multiple Command Remote DoS

medium Nessus Plugin ID 35328

Synopsis

The remote FTP server is affected by a denial of service vulnerability.

Description

The installed version of Serv-U 7.x is earlier than 7.4.0.0, and is therefore affected by a denial of service vulnerability. By using a specially crafted command such as XCRC, STOU, DSIZ, AVBL, RNTO, or RMDA, it may be possible for an authenticated attacker to render the FTP server temporarily unresponsive.

Solution

Upgrade to Serv-U version 7.4.0.0 or later.

See Also

https://support.solarwinds.com/Success_Center/Serv-U_Managed_File_Transfer_Serv-U_FTP_Server/Serv-U_Documentation/release_notes

Plugin Details

Severity: Medium

ID: 35328

File Name: servu_7_4_0_0.nasl

Version: 1.13

Type: remote

Family: FTP

Published: 1/9/2009

Updated: 4/11/2022

Configuration: Enable thorough checks

Supported Sensors: Nessus

Risk Information

CVSS v2

Risk Factor: Medium

Base Score: 4

Temporal Score: 3

Vector: CVSS2#AV:N/AC:L/Au:S/C:N/I:N/A:P

Vulnerability Information

CPE: cpe:/a:serv-u:serv-u

Required KB Items: ftp/servu

Exploit Ease: No known exploits are available

Reference Information

BID: 33180

SECUNIA: 33411