FTP Serv-U vulnerable to a remotely exploitable buffer overflow (SITE)
2 Dec. 1999
Summary
FTP Serv-U daemon version 2.5, is a solution for file sharing across the Internet via the FTP protocol. This server is vulnerable to a buffer overflow that causes the FTP Server to crash and execute arbitrary code when an attacker executes the SITE command.
Credit:
This vulnerability has been discovered by: Ussr Labs.
UssrLabs found a Local/Remote DoS Attack in Serv-U FTP-Server. The buffer overflow is caused by a malformed SITE command. It can be used to execute arbitrary code, compromising the system security.