[vulnwatch] WFTPD Pro Server 3.21 MLST Command Denial of Service Vulnerability

From: lion (lion_at_cnhonker.net)
Date: 08/29/04

  • Next message: Steven Van Acker: "Possible root compromose with bsdmainutils 6.0.x < 6.0.15 (Debian testing/unstable)"
    Date: Mon, 30 Aug 2004 02:38:49 +0800
    To: "bugtraq" <bugtraq@securityfocus.com>
    
    
    

    [vulnwatch] WFTPD Pro Server 3.21 MLST Command Denial of Service Vulnerability

    www.cnhonker.com
    Security Advisory

    Advisory Name: WFTPD Pro Server 3.21 MLST Command Denial of Service Vulnerability
    Release Date: 08/30/2004
    Affected version: WFTPD Pro Server 3.21 Release 3
    Author: lion <lion@cnhonker.net>

    Overview:

    A vulnerability has been found in WFTPD Pro Server. The problem \
    is When a user logged in, send a "mlst" command to target will crash the Server.

    Exploit:

    PoC exploit attached.

    About HUC:

    HUC is still alive.

    
    



  • Next message: Steven Van Acker: "Possible root compromose with bsdmainutils 6.0.x < 6.0.15 (Debian testing/unstable)"