CVE-2005-0850: Input Validation
Published Mar 24, 2005
·Updated
FileZilla FTP server before 0.9.6 allows remote attackers to cause a denial of service via a request for a filename containing an MS-DOS device name such as CON, NUL, COM1, LPT1, and others.
Affected Software
1 affected component
Filezilla-project Filezilla Server<0.9.6
Remediation
Patch Available
Event History
Mar 24, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-0850?
CVE-2005-0850 is classified as a denial of service vulnerability that can disrupt the operation of the FileZilla FTP server.
2
How do I fix CVE-2005-0850?
To mitigate CVE-2005-0850, upgrade to FileZilla Server version 0.9.6 or later.
3
What versions of FileZilla are affected by CVE-2005-0850?
CVE-2005-0850 affects all versions of FileZilla FTP server prior to 0.9.6.
4
Can CVE-2005-0850 be exploited remotely?
Yes, CVE-2005-0850 can be exploited remotely by sending crafted requests to the FileZilla FTP server.
5
What kind of attack does CVE-2005-0850 enable?
CVE-2005-0850 enables a remote denial of service attack that can render the FTP server unresponsive.