First published: Thu Sep 20 2001(Updated: )
NetWin SurgeFTP 2.0a and 1.0b allows a remote attacker to cause a denial of service (crash) via a CD command to a directory with an MS-DOS device name such as con.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
NetWin SurgeFTP | =1.0b | |
NetWin SurgeFTP | =2.0a |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-0696 has a severity rating associated with denial of service vulnerabilities.
CVE-2001-0696 allows a remote attacker to crash the server by issuing a CD command to a directory with an MS-DOS device name.
CVE-2001-0696 affects NetWin SurgeFTP versions 1.0b and 2.0a.
To fix CVE-2001-0696, update to a patched version of NetWin SurgeFTP that addresses this vulnerability.
Yes, CVE-2001-0696 can be exploited remotely, allowing attackers to crash the server.