CVE-2004-2111: Buffer Overflow
Published Dec 31, 2004
·Updated
Stack-based buffer overflow in the site chmod command in Serv-U FTP Server before 4.2 allows remote attackers to execute arbitrary code via a long filename.
Affected Software
8 affected components
SolarWinds Serv-u File Server<=4.1.0.3
SolarWinds Serv-u File Server=3.0.0.16
SolarWinds Serv-u File Server=3.0.0.17
SolarWinds Serv-u File Server=3.1.0.0
SolarWinds Serv-u File Server=3.1.0.1
SolarWinds Serv-u File Server=3.1.0.3
SolarWinds Serv-u File Server=4.0.0.4
SolarWinds Serv-u File Server=4.1.0.0
Event History
Dec 31, 2004
CVE Published
05:00 AM
May 27, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-2111?
CVE-2004-2111 is rated as a critical severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2004-2111?
To fix CVE-2004-2111, upgrade the Serv-U FTP Server to version 4.1.0.4 or later.
3
What versions of Serv-U FTP Server are affected by CVE-2004-2111?
CVE-2004-2111 affects Serv-U FTP Server versions up to and including 4.1.0.3.
4
What type of vulnerability is CVE-2004-2111?
CVE-2004-2111 is a stack-based buffer overflow vulnerability.
5
Can CVE-2004-2111 be exploited remotely?
Yes, CVE-2004-2111 can be exploited remotely by attackers using a long filename.