CVE-2004-1675: Input Validation
Serv-U FTP server 4.x and 5.x allows remote attackers to cause a denial of service (application crash) via a STORE UNIQUE (STOU) command with an MS-DOS device name argument such as (1) COM1, (2) LPT1, (3) PRN, or (4) AUX.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-1675?
CVE-2004-1675 has a severity rating classified as medium due to its ability to cause a denial of service.
How do I fix CVE-2004-1675?
To fix CVE-2004-1675, it is recommended to upgrade to the latest version of the Serv-U FTP server that addresses this vulnerability.
Which versions are affected by CVE-2004-1675?
CVE-2004-1675 affects Serv-U FTP server versions 4.x and 5.x, specifically including versions 4.0.0.4, 4.1.0.0, 4.1.0.3, 5.0.0.0, 5.0.0.4, 5.0.0.9, 5.0.0.11, 5.1.0.0, 5.2.0.0, and 5.2.0.1.
What type of attack does CVE-2004-1675 facilitate?
CVE-2004-1675 facilitates a denial of service attack by causing the Serv-U FTP server to crash when specific MS-DOS device names are used in a STORE UNIQUE (STOU) command.
Is CVE-2004-1675 a remote vulnerability?
Yes, CVE-2004-1675 is a remote vulnerability, allowing attackers to exploit it without physical access to the server.