Vulnerabilities > CVE-2004-0342 - Off-by-one Error vulnerability in Wftpd PRO Server Project Wftpd PRO Server 3.21
Attack vector
LOCAL Attack complexity
LOW Privileges required
LOW Confidentiality impact
NONE Integrity impact
NONE Availability impact
HIGH Summary
WFTPD Pro Server 3.21 Release 1, with the XeroxDocutech option enabled, allows local users to cause a denial of service (crash) via a (1) MKD or (2) XMKD command that causes an absolute path of 260 characters to be used, which overwrites a cookie with a null character, possibly due to an off-by-one error.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Common Weakness Enumeration (CWE)
Nessus
NASL family | FTP |
NASL id | WFTP_321_OVERFLOW.NASL |
description | The remote FTP server is vulnerable to at least two remote stack-based overflows and two Denial of Service attacks. An attacker can use these flaws to gain remote access to the WFTPD server. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 12083 |
published | 2004-02-29 |
reporter | This script is Copyright (C) 2004-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/12083 |
title | WFTP 3.21 Multiple Vulnerabilities (OF, DoS) |
code |
|
References
- http://marc.info/?l=bugtraq&m=107801142924976&w=2
- http://marc.info/?l=bugtraq&m=107801142924976&w=2
- http://secunia.com/advisories/11001
- http://secunia.com/advisories/11001
- http://www.osvdb.org/4116
- http://www.osvdb.org/4116
- http://www.securityfocus.com/bid/9767
- http://www.securityfocus.com/bid/9767
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15342
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15342