CVE-2007-3768: High severity Netwin SurgeFTP vulnerability
Published Jul 15, 2007
·Updated
The mirror mechanism in SurgeFTP 2.3a1 allows user-assisted, remote FTP servers to cause a denial of service (restart) via a malformed response to a PASV command.
Affected Software
1 affected component
Netwin SurgeFTP<=2.3a1
Remediation
Patch Available
Event History
Jul 15, 2007
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-3768?
CVE-2007-3768 is classified as a denial of service vulnerability that can cause a restart of the affected system.
2
How do I fix CVE-2007-3768?
To fix CVE-2007-3768, it is recommended to upgrade to a newer version of SurgeFTP that does not have this vulnerability.
3
Which versions of SurgeFTP are affected by CVE-2007-3768?
SurgeFTP version 2.3a1 and earlier are affected by CVE-2007-3768.
4
What type of attack does CVE-2007-3768 involve?
CVE-2007-3768 involves a user-assisted attack where a malformed PASV command response can lead to a denial of service.
5
Is CVE-2007-3768 still a risk for current FTP services?
If you are using SurgeFTP version 2.3a1 or earlier, CVE-2007-3768 remains a risk, and it should be addressed immediately.