CVE-2001-0697: Medium severity Netwin SurgeFTP vulnerability
Published Sep 20, 2001
·Updated
NetWin SurgeFTP prior to 1.1h allows a remote attacker to cause a denial of service (crash) via an 'ls ..' command.
Affected Software
1 affected component
Netwin SurgeFTP<=1.1h
Remediation
Patch Available
Event History
Sep 20, 2001
CVE Published
04:00 AM
Mar 9, 2002
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-0697?
CVE-2001-0697 is classified as a denial of service vulnerability.
2
How do I fix CVE-2001-0697?
To resolve CVE-2001-0697, upgrade SurgeFTP to version 1.1h or later.
3
What does CVE-2001-0697 allow an attacker to do?
CVE-2001-0697 allows a remote attacker to cause a denial of service by issuing an 'ls ..' command.
4
Which versions of NetWin SurgeFTP are affected by CVE-2001-0697?
CVE-2001-0697 affects all versions of NetWin SurgeFTP prior to 1.1h.
5
Is there a workaround for CVE-2001-0697?
There is no specific workaround for CVE-2001-0697; upgrading to a secure version is recommended.