First published: Sat Sep 11 2004(Updated: )
Serv-U FTP server 4.x and 5.x allows remote attackers to cause a denial of service (application crash) via a STORE UNIQUE (STOU) command with an MS-DOS device name argument such as (1) COM1, (2) LPT1, (3) PRN, or (4) AUX.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SolarWinds Serv-U File Server | =4.0.0.4 | |
SolarWinds Serv-U File Server | =4.1.0.0 | |
SolarWinds Serv-U File Server | =4.1.0.3 | |
SolarWinds Serv-U File Server | =5.0.0.0 | |
SolarWinds Serv-U File Server | =5.0.0.4 | |
SolarWinds Serv-U File Server | =5.0.0.9 | |
SolarWinds Serv-U File Server | =5.0.0.11 | |
SolarWinds Serv-U File Server | =5.1.0.0 | |
SolarWinds Serv-U File Server | =5.2.0.0 | |
SolarWinds Serv-U File Server | =5.2.0.1 | |
SolarWinds Serv-U | =4.0.0.4 | |
SolarWinds Serv-U | =4.1.0.0 | |
SolarWinds Serv-U | =4.1.0.3 | |
SolarWinds Serv-U | =5.0.0.0 | |
SolarWinds Serv-U | =5.0.0.4 | |
SolarWinds Serv-U | =5.0.0.9 | |
SolarWinds Serv-U | =5.0.0.11 | |
SolarWinds Serv-U | =5.1.0.0 | |
SolarWinds Serv-U | =5.2.0.0 | |
SolarWinds Serv-U | =5.2.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-1675 has a severity rating classified as medium due to its ability to cause a denial of service.
To fix CVE-2004-1675, it is recommended to upgrade to the latest version of the Serv-U FTP server that addresses this vulnerability.
CVE-2004-1675 affects Serv-U FTP server versions 4.x and 5.x, specifically including versions 4.0.0.4, 4.1.0.0, 4.1.0.3, 5.0.0.0, 5.0.0.4, 5.0.0.9, 5.0.0.11, 5.1.0.0, 5.2.0.0, and 5.2.0.1.
CVE-2004-1675 facilitates a denial of service attack by causing the Serv-U FTP server to crash when specific MS-DOS device names are used in a STORE UNIQUE (STOU) command.
Yes, CVE-2004-1675 is a remote vulnerability, allowing attackers to exploit it without physical access to the server.