War FTP Daemon CWD/MKD Overflow DoS

medium Nessus Network Monitor Plugin ID 1849

Synopsis

The remote host is vulnerable to a buffer overflow.

Description

The version of the War FTP Daemon running on this host is vulnerable to a buffer overflow attack. This is due to improper bounds checking within the code that handles both the CWD and MKD commands. By exploiting this vulnerability, it is possible to crash the server, and potentially run arbitrary commands on this system.

Solution

Upgrade or patch according to vendor recommendations.

Plugin Details

Severity: Medium

ID: 1849

Family: FTP Servers

Published: 8/20/2004

Updated: 3/6/2019

Nessus ID: 11205

Risk Information

VPR

Risk Factor: Medium

Score: 4.4

CVSS v2

Risk Factor: Medium

Base Score: 4

Temporal Score: 3.5

Vector: CVSS2#AV:N/AC:L/Au:S/C:N/I:N/A:P

CVSS v3

Risk Factor: Medium

Base Score: 4.3

Temporal Score: 4.1

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Temporal Vector: CVSS:3.0/E:H/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:jgaa:warftpd

Reference Information

CVE: CVE-2000-0131

BID: 966