Vulnerabilities > CVE-1999-0079 - Unspecified vulnerability in Bisonware FTP Server 3.5

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
PARTIAL
network
low complexity
bisonware
nessus

Summary

Remote attackers can cause a denial of service in FTP by issuing multiple PASV commands, causing the server to run out of available ports.

Vulnerable Configurations

Part Description Count
Application
Bisonware
1

Nessus

NASL familyFTP
NASL idFTP_PASV_DOS.NASL
descriptionThe remote FTP server allows users to make any amount of PASV commands, thus blocking the free ports for legitimate services and consuming file descriptors. An unauthenticated attacker could exploit this flaw to crash the FTP service.
last seen2020-06-01
modified2020-06-02
plugin id10085
published1999-06-22
reporterThis script is Copyright (C) 1999-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/10085
titleMultiple Vendor FTP Multiple PASV Command Port Exhaustion DoS