vendor:
Serv-U FTP Server
by:
mandragore
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Serv-U FTP Server
Affected Version From: 4.1.0.0
Affected Version To: 4.1.0.0
Patch Exists: NO
Related CWE: CVE-2004-2707
CPE: a:rhinosoft:serv-u_ftp_server:4.1.0.0
Platforms Tested:
Buffer Overflow in RhinoSoft Serv-U FTP Server
The RhinoSoft Serv-U FTP Server is prone to a buffer overflow vulnerability. This vulnerability occurs when a 'site chmod' command is issued on a non-existent file with an excessively long filename. This can result in an internal buffer overrun, causing the FTP server to fail and potentially allowing for the execution of arbitrary code.
Mitigation:
Upgrade to a patched version of Serv-U FTP Server.