CVE-2004-1848: Medium severity Ipswitch Ws Ftp Server vulnerability
Published Dec 31, 2004
·Updated
Ipswitch WSFTP Server 4.0.2 allows remote attackers to cause a denial of service (disk consumption) and bypass file size restrictions via a REST command with a large size argument, followed by a STOR of a smaller file.
Affected Software
38 affected components
Ipswitch Ws Ftp Server=4.01
Ipswitch Ws Ftp Server=3.0_1
Progress Ipswitch Ws Ftp Server=1.0.1
Progress Ipswitch Ws Ftp Server=1.0.2
Progress Ipswitch Ws Ftp Server=1.0.3
Progress Ipswitch Ws Ftp Server=1.0.4
Progress Ipswitch Ws Ftp Server=1.0.5
Progress Ipswitch Ws Ftp Server=2.0
Progress Ipswitch Ws Ftp Server=2.0.1
Progress Ipswitch Ws Ftp Server=2.0.2
Progress Ipswitch Ws Ftp Server=2.0.3
Progress Ipswitch Ws Ftp Server=2.0.4
Progress Ipswitch Ws Ftp Server=3.0
Progress Ipswitch Ws Ftp Server=3.1
Progress Ipswitch Ws Ftp Server=3.1.1
Progress Ipswitch Ws Ftp Server=3.1.2
Progress Ipswitch Ws Ftp Server=3.1.3
Progress Ipswitch Ws Ftp Server=3.4
Progress Ipswitch Ws Ftp Server=4.0
Progress Ipswitch Ws Ftp Server=4.0.2
Progress Ws Ftp Server=1.0.1
Progress Ws Ftp Server=1.0.2
Progress Ws Ftp Server=1.0.3
Progress Ws Ftp Server=1.0.4
Progress Ws Ftp Server=1.0.5
Progress Ws Ftp Server=2.0
Progress Ws Ftp Server=2.0.1
Progress Ws Ftp Server=2.0.2
Progress Ws Ftp Server=2.0.3
Progress Ws Ftp Server=2.0.4
Progress Ws Ftp Server=3.0
Progress Ws Ftp Server=3.1
Progress Ws Ftp Server=3.1.1
Progress Ws Ftp Server=3.1.2
Progress Ws Ftp Server=3.1.3
Progress Ws Ftp Server=3.4
Progress Ws Ftp Server=4.0
Progress Ws Ftp Server=4.0.2
Remediation
Patch Available
Event History
Dec 31, 2004
CVE Published
05:00 AM
May 10, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-1848?
The severity of CVE-2004-1848 is classified as a denial of service vulnerability.
2
How do I fix CVE-2004-1848?
To fix CVE-2004-1848, upgrade to a patched version of Ipswitch WS_FTP Server that does not allow REST commands with large size arguments.
3
What versions are affected by CVE-2004-1848?
CVE-2004-1848 affects Ipswitch WS_FTP Server versions up to 4.0.2 and various previous versions.
4
What kind of attack does CVE-2004-1848 facilitate?
CVE-2004-1848 facilitates a disk consumption denial of service attack by manipulating file uploads.
5
Who is impacted by CVE-2004-1848?
Any users of Ipswitch WS_FTP Server versions 4.0.2 and older are at risk from CVE-2004-1848.