First published: Thu Feb 10 2005(Updated: )
TFTP in 3Com 3CDaemon 2.0 revision 10 allows remote attackers to cause a denial of service (application crash) via a GET request containing an MS-DOS device name.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
3Com 3CDaemon | =2.0-revision_10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-0275 is classified as a denial of service vulnerability.
To mitigate CVE-2005-0275, consider upgrading from 3Com 3CDaemon 2.0 revision 10 to a more secure version or disable TFTP services.
CVE-2005-0275 is caused by the handling of GET requests containing MS-DOS device names, which leads to application crashes.
CVE-2005-0275 specifically affects 3Com 3CDaemon version 2.0 revision 10.
Yes, CVE-2005-0275 can be exploited remotely, allowing attackers to cause a denial of service.