CVE-2002-2393: Input Validation
Published Dec 31, 2002
·Updated
Serv-U FTP server 3.0, 3.1 and 4.0.0.4 does not accept new connections while validating user folder access rights, which allows remote attackers to cause a denial of service (no new connections) via a series of MKD commands.
Affected Software
2 affected components
SolarWinds Serv-u File Server=3.1.0.0
SolarWinds Serv-u File Server=4.0.0.4
Remediation
Patch Available
Event History
Dec 31, 2002
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
RemedyDescriptionSeverityWeaknessAffected Software
Oct 31, 2007
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-2393?
CVE-2002-2393 is classified as a denial of service vulnerability.
2
Which versions of Serv-U File Server are affected by CVE-2002-2393?
CVE-2002-2393 affects Serv-U File Server versions 3.0, 3.1, and 4.0.0.4.
3
How does CVE-2002-2393 allow denial of service?
CVE-2002-2393 allows denial of service by preventing new connections through a series of MKD commands.
4
What is the impact of CVE-2002-2393 on the Serv-U FTP server?
The impact of CVE-2002-2393 is that it stops new connections from being established on the affected Serv-U FTP server.
5
How can I mitigate CVE-2002-2393?
Mitigating CVE-2002-2393 involves upgrading to a non-vulnerable version of the Serv-U File Server.