First published: Thu Dec 06 2007(Updated: )
The dataconn function in ftpd.c in netkit ftpd (netkit-ftpd) 0.17, when certain modifications to support SSL have been introduced, calls fclose on an uninitialized file stream, which allows remote attackers to cause a denial of service (daemon crash) and possibly have unspecified other impact via some types of FTP over SSL protocol behavior, as demonstrated by breaking a passive FTP DATA connection in a way that triggers an error in the server's SSL_accept function. NOTE: the netkit ftp issue is covered by CVE-2007-5769.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Netkit | =0.17 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-6263 has a moderate severity level due to its potential to cause a denial of service.
To fix CVE-2007-6263, upgrade to a patched version of netkit ftpd that addresses the issue.
CVE-2007-6263 can cause a daemon crash, leading to a denial of service on the affected system.
CVE-2007-6263 specifically affects netkit-ftpd version 0.17.
Yes, CVE-2007-6263 can be exploited remotely by attackers due to the nature of the vulnerability.