vendor:
TinyFTPD
by:
[Oo]
7,5
CVSS
HIGH
Denial of Service (DoS)
400
CWE
Product Name: TinyFTPD
Affected Version From: 1.4 and earlier
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2006
TinyFTPD <= 1.4 USER command D.O.S
A denial of service vulnerability exists in TinyFTPD 1.4 and earlier. A remote attacker can send a specially crafted USER command with an overly long argument to cause the service to crash.
Mitigation:
Upgrade to the latest version of TinyFTPD.