Serv-U is a "powerful, easy-to-use, award-winning FTP server" created by Rob Beckers. A vulnerability in the product allows a remote user to cause the server to fail by sending a malformed LIST command to the server.
Credit:
SecurITeam would like to thank STORM for finding this vulnerability.
Vulnerable Systems:
* Serv-U version 5.0.0.4 and prior
Immune Systems:
* Serv-U 5.0.0.6 and newer
A user issuing a long parameter (around 134 bytes) as a value for a LIST command (using the -l: parameter for that LIST command), can cause the server to try and read a value that is outside the memory location of the Serv-U's memory, this will cause an exception to be triggered (an unhandled exception), which in turn causes the program to crash.