CVE-1999-0838: Buffer Overflow
Buffer overflow in Serv-U FTP 2.5 allows remote users to conduct a denial of service via the SITE command.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
SolarWinds Serv-U FTP Serverfrom your environment.Uninstall Serv-U if the FTP service is not required in your environment to eliminate the vulnerable software.
- Configuration
Disable or restrict the FTP SITE command on the Serv-U server to prevent exploitation via the SITE command (disable SITE support or limit which SITE subcommands are accepted).
SolarWinds Serv-U FTP Server SITE command = disabled - Compensating control
Restrict access to the Serv-U FTP service to trusted IP addresses or networks (via firewall rules, ACLs, or VPN) and block or rate-limit connections from untrusted hosts to reduce exposure to remote attacks.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0838?
CVE-1999-0838 has a high severity rating due to the potential for remote denial of service attacks.
How do I fix CVE-1999-0838?
To fix CVE-1999-0838, update the Serv-U FTP server to a version later than 2.5a that addresses this buffer overflow vulnerability.
Who is affected by CVE-1999-0838?
Users of Deerfield Serv-U FTP version 2.5a are directly affected by CVE-1999-0838.
What type of vulnerability is CVE-1999-0838?
CVE-1999-0838 is classified as a buffer overflow vulnerability.
Can CVE-1999-0838 be exploited remotely?
Yes, CVE-1999-0838 can be exploited remotely via the SITE command.