CVE-2001-0696: Medium severity Netwin SurgeFTP vulnerability
Published Sep 20, 2001
·Updated
NetWin SurgeFTP 2.0a and 1.0b allows a remote attacker to cause a denial of service (crash) via a CD command to a directory with an MS-DOS device name such as con.
Affected Software
2 affected components
Netwin SurgeFTP=1.0b
Netwin SurgeFTP=2.0a
Remediation
Patch Available
Patch Available
Event History
Sep 20, 2001
CVE Published
04:00 AM
Mar 9, 2002
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-0696?
CVE-2001-0696 has a severity rating associated with denial of service vulnerabilities.
2
How does CVE-2001-0696 affect NetWin SurgeFTP?
CVE-2001-0696 allows a remote attacker to crash the server by issuing a CD command to a directory with an MS-DOS device name.
3
What versions of SurgeFTP are vulnerable to CVE-2001-0696?
CVE-2001-0696 affects NetWin SurgeFTP versions 1.0b and 2.0a.
4
How do I fix CVE-2001-0696?
To fix CVE-2001-0696, update to a patched version of NetWin SurgeFTP that addresses this vulnerability.
5
Can CVE-2001-0696 be exploited remotely?
Yes, CVE-2001-0696 can be exploited remotely, allowing attackers to crash the server.