CVE-2004-1992: Buffer Overflow
Published Apr 20, 2004
·Updated
Buffer overflow in Serv-U FTP server before 5.0.0.6 allows remote attackers to cause a denial of service (crash) via a long -l parameter, which triggers an out-of-bounds read.
Affected Software
10 affected components
SolarWinds Serv-u File Server<=5.0.0.4
SolarWinds Serv-u File Server=3.0.0.16
SolarWinds Serv-u File Server=3.0.0.17
SolarWinds Serv-u File Server=3.1.0.0
SolarWinds Serv-u File Server=3.1.0.1
SolarWinds Serv-u File Server=3.1.0.3
SolarWinds Serv-u File Server=4.0.0.4
SolarWinds Serv-u File Server=4.1.0.0
SolarWinds Serv-u File Server=4.1.0.3
SolarWinds Serv-u File Server=5.0.0.0
Remediation
Patch Available
Event History
Apr 20, 2004
CVE Published
04:00 AM
May 10, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-1992?
CVE-2004-1992 is classified as a moderate severity vulnerability due to its potential to cause denial of service.
2
How do I fix CVE-2004-1992?
To fix CVE-2004-1992, you should upgrade the Serv-U FTP server to version 5.0.0.6 or later.
3
What software versions are affected by CVE-2004-1992?
CVE-2004-1992 affects Serv-U FTP server versions prior to 5.0.0.6, including 3.x and 4.x versions.
4
Can CVE-2004-1992 be exploited remotely?
Yes, CVE-2004-1992 can be exploited remotely by sending a specially crafted long -l parameter.
5
What type of vulnerability is CVE-2004-1992?
CVE-2004-1992 is a buffer overflow vulnerability that leads to an out-of-bounds read.