First published: Mon Apr 05 2010(Updated: )
NWFTPD.nlm before 5.04.25 in the FTP server in Novell NetWare does not promptly close DS sessions, which allows remote attackers to cause a denial of service (connection slot exhaustion) by establishing many FTP sessions that persist for the lifetime of a DS session.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Novell Netware Ftp Server | ||
Novell NetWare |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-2767 is considered a medium severity vulnerability due to its potential for denial of service through connection slot exhaustion.
To fix CVE-2004-2767, upgrade the NWFTPD.nlm to version 5.04.25 or later.
CVE-2004-2767 affects Novell NetWare and the FTP server versions prior to 5.04.25.
The impact of CVE-2004-2767 is a denial of service that can prevent legitimate users from establishing FTP sessions.
Yes, CVE-2004-2767 can be exploited remotely by an attacker who establishes multiple FTP sessions.