Vulnerabilities > CVE-2005-0851 - Infinite Loop vulnerability in Filezilla-Project Filezilla Server
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
NONE Integrity impact
NONE Availability impact
PARTIAL Summary
FileZilla FTP server before 0.9.6, when using MODE Z (zlib compression), allows remote attackers to cause a denial of service (infinite loop) via certain file uploads or directory listings.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Common Weakness Enumeration (CWE)
Nessus
NASL family | FTP |
NASL id | FILEZILLA_DENIAL.NASL |
description | The remote host is running a version of FileZilla server with the following denial of service vulnerabilities : - Requesting a file containing the reserved name of a DOS device (e.g. CON, NUL, COM1, etc.) can cause the server to freeze. - Downloading a file or directory listing with MODE Z enabled (zlib compression) can cause an infinite loop. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 17593 |
published | 2005-03-22 |
reporter | This script is Copyright (C) 2005-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/17593 |
title | FileZilla FTP Server Multiple DoS |
code |
|