First published: Tue Apr 20 2004(Updated: )
Buffer overflow in Serv-U FTP server before 5.0.0.6 allows remote attackers to cause a denial of service (crash) via a long -l parameter, which triggers an out-of-bounds read.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SolarWinds Serv-U File Server | =3.0.0.16 | |
SolarWinds Serv-U File Server | =3.0.0.17 | |
SolarWinds Serv-U File Server | =3.1.0.0 | |
SolarWinds Serv-U File Server | =3.1.0.1 | |
SolarWinds Serv-U File Server | =3.1.0.3 | |
SolarWinds Serv-U File Server | =4.0.0.4 | |
SolarWinds Serv-U File Server | =4.1.0.0 | |
SolarWinds Serv-U File Server | =4.1.0.3 | |
SolarWinds Serv-U File Server | =5.0.0.0 | |
SolarWinds Serv-U File Server | <=5.0.0.4 | |
SolarWinds Serv-U | <=5.0.0.4 | |
SolarWinds Serv-U | =3.0.0.16 | |
SolarWinds Serv-U | =3.0.0.17 | |
SolarWinds Serv-U | =3.1.0.0 | |
SolarWinds Serv-U | =3.1.0.1 | |
SolarWinds Serv-U | =3.1.0.3 | |
SolarWinds Serv-U | =4.0.0.4 | |
SolarWinds Serv-U | =4.1.0.0 | |
SolarWinds Serv-U | =4.1.0.3 | |
SolarWinds Serv-U | =5.0.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-1992 is classified as a moderate severity vulnerability due to its potential to cause denial of service.
To fix CVE-2004-1992, you should upgrade the Serv-U FTP server to version 5.0.0.6 or later.
CVE-2004-1992 affects Serv-U FTP server versions prior to 5.0.0.6, including 3.x and 4.x versions.
Yes, CVE-2004-1992 can be exploited remotely by sending a specially crafted long -l parameter.
CVE-2004-1992 is a buffer overflow vulnerability that leads to an out-of-bounds read.