First published: Mon Apr 05 2010(Updated: )
NWFTPD.nlm before 5.02i in the FTP server in Novell NetWare does not properly listen for data connections, which allows remote attackers to cause a denial of service (abend) via multiple FTP sessions.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Novell NetWare FTP Server | <=5.02b | |
Novell NetWare FTP Server | =5.01i | |
Novell NetWare FTP Server | =5.01o | |
Novell NetWare FTP Server | =5.01w | |
Novell NetWare FTP Server | =5.01y | |
Novell NetWare FTP Server | =5.1 | |
Novell NetWare FTP Server | =6.0 | |
Novell NetWare FTP Server | =6.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-2434 is classified as a denial of service vulnerability.
To mitigate CVE-2002-2434, upgrade to Novell NetWare FTP Server version 5.02i or later.
CVE-2002-2434 affects Novell NetWare FTP Server versions up to and including 5.02b and specific earlier versions like 5.01i, 5.01o, 5.01w, and 5.01y.
Yes, CVE-2002-2434 can be exploited remotely through multiple FTP sessions.
CVE-2002-2434 enables attackers to cause a denial of service attack leading to system abend.