War FTP Daemon CWD/MKD Overflow DoS

Medium Nessus Network Monitor Plugin ID 1849

Synopsis

The remote host is vulnerable to a buffer overflow.

Description

The version of the War FTP Daemon running on this host is vulnerable to a buffer overflow attack. This is due to improper bounds checking within the code that handles both the CWD and MKD commands. By exploiting this vulnerability, it is possible to crash the server, and potentially run arbitrary commands on this system.

Solution

Upgrade or patch according to vendor recommendations.

Plugin Details

Severity: Medium

ID: 1849

File Name: 1849.prm

Family: FTP Servers

Published: 2004/08/20

Modified: 2016/01/30

Dependencies: 1852

Nessus ID: 11205

Risk Information

Risk Factor: Medium

CVSSv2

Base Score: 4

Temporal Score: 3.5

Vector: CVSS2#AV:N/AC:L/Au:S/C:N/I:N/A:P

Temporal Vector: CVSS2#E:H/RL:OF/RC:C

CVSSv3

Base Score: 4.3

Temporal Score: 4.1

Vector: CVSS3#AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Temporal Vector: CVSS3#E:H/RL:O/RC:C

Reference Information

CVE: CVE-2000-0131

BID: 966