CVE-2005-3467: Input Validation
Serv-U FTP Server before 6.1.0.4 allows attackers to cause a denial of service (crash) via (1) malformed packets and possibly other unspecified issues with unknown impact and attack vectors including (2) use of "~" in a pathname, and (3) memory consumption of the daemon. NOTE: it is not clear whether items (2) and above are vulnerabilities.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-3467?
CVE-2005-3467 is classified as a denial of service vulnerability that can crash the Serv-U FTP Server.
How do I fix CVE-2005-3467?
To fix CVE-2005-3467, upgrade the Serv-U FTP Server to version 6.1.0.4 or later.
Which versions of Serv-U FTP Server are affected by CVE-2005-3467?
CVE-2005-3467 affects all versions of Serv-U FTP Server prior to 6.1.0.4.
What types of attacks are possible with CVE-2005-3467?
Attackers can exploit CVE-2005-3467 through malformed packets and pathname manipulation.
What impact does CVE-2005-3467 have on the system?
CVE-2005-3467 can lead to a denial of service, causing the FTP server to crash.