Vulnerabilities > CVE-2009-3655 - Denial-Of-Service vulnerability in Serv-U

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
PARTIAL
network
low complexity
solarwinds

Summary

Rhino Software Serv-U 7.0.0.1 through 8.2.0.3 allows remote attackers to cause a denial of service (server crash) via unspecified vectors related to the "SITE SET TRANSFERPROGRESS ON" FTP command.

Oval

accepted2011-08-22T04:01:09.581-04:00
classvulnerability
contributors
  • nameSharath S
    organizationSecPod Technologies
  • nameShane Shaffer
    organizationG2, Inc.
definition_extensions
commentRhino Software Serv-U is installed
ovaloval:org.mitre.oval:def:5875
descriptionRhino Software Serv-U 7.0.0.1 through 8.2.0.3 allows remote attackers to cause a denial of service (server crash) via unspecified vectors related to the "SITE SET TRANSFERPROGRESS ON" FTP command.
familywindows
idoval:org.mitre.oval:def:5798
statusaccepted
submitted2009-11-25T18:28:46
title"SITE SET TRANSFERPROGRESS ON" FTP Command Denial of Service Vulnerability in Rhino Software Serv-U
version5