CVE-2008-5666: Low severity Wftpserver Winftp Ftp Server vulnerability
Published Dec 18, 2008
·Updated
WinFTP FTP Server 2.3.0, when passive (aka PASV) mode is used, allows remote authenticated users to cause a denial of service via a sequence of FTP sessions that include an invalid "NLST -1" command.
Affected Software
1 affected component
Wftpserver Winftp Ftp Server=2.3.0
Event History
Dec 18, 2008
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Dec 19, 2008
Data Sourced
via NVD·01:52 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2008-5666?
CVE-2008-5666 is rated as a medium severity vulnerability due to its potential to cause a denial of service.
2
How do I fix CVE-2008-5666?
To fix CVE-2008-5666, upgrade to a patched version of WinFTP FTP Server that addresses the issue.
3
Who is affected by CVE-2008-5666?
CVE-2008-5666 affects remote authenticated users of WinFTP FTP Server version 2.3.0.
4
What type of attack does CVE-2008-5666 enable?
CVE-2008-5666 enables a denial of service attack through malformed FTP commands.
5
What is the exploit mechanism for CVE-2008-5666?
The exploit mechanism for CVE-2008-5666 involves issuing a sequence of FTP sessions that include an invalid 'NLST -1' command.