CVE-2004-2767: Medium severity Novell Netware Ftp Server vulnerability
NWFTPD.nlm before 5.04.25 in the FTP server in Novell NetWare does not promptly close DS sessions, which allows remote attackers to cause a denial of service (connection slot exhaustion) by establishing many FTP sessions that persist for the lifetime of a DS session.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2004-2767?
CVE-2004-2767 is considered a medium severity vulnerability due to its potential for denial of service through connection slot exhaustion.
How do I fix CVE-2004-2767?
To fix CVE-2004-2767, upgrade the NWFTPD.nlm to version 5.04.25 or later.
What systems are affected by CVE-2004-2767?
CVE-2004-2767 affects Novell NetWare and the FTP server versions prior to 5.04.25.
What is the impact of CVE-2004-2767?
The impact of CVE-2004-2767 is a denial of service that can prevent legitimate users from establishing FTP sessions.
Can CVE-2004-2767 be exploited remotely?
Yes, CVE-2004-2767 can be exploited remotely by an attacker who establishes multiple FTP sessions.