vendor:
Pure-FTPd
by:
Kingcope
7,5
CVSS
HIGH
Null Pointer Dereference
476
CWE
Product Name: Pure-FTPd
Affected Version From: 1.0.21
Affected Version To: 1.0.36
Patch Exists: YES
Related CWE: N/A
CPE: a:pureftpd:pure-ftpd
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: CentOS 6.2, Ubuntu 8.04
2009
Pure-FTPd Crash PoC (Null Pointer Dereference)
This PoC exploits a null pointer dereference vulnerability in Pure-FTPd. It has been tested with Pure-FTPd v1.0.21 on CentOS 6.2 and Ubuntu 8.04. The latest version (v1.0.36) is not affected. The PoC sends a specially crafted PASV command to the FTP server, which causes a segmentation fault and crashes the server.
Mitigation:
Upgrade to the latest version of Pure-FTPd.