First published: Fri May 02 2014(Updated: )
Core FTP Server 1.2 before build 515 allows remote attackers to cause a denial of service (reachable assertion and crash) via an AUTH SSL command with malformed data, as demonstrated by pressing the enter key twice.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tsolucio Corebos | =1.2 | |
=1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-1441 is classified as a denial of service vulnerability.
CVE-2014-1441 affects Core FTP Server versions prior to 1.2 build 515.
CVE-2014-1441 allows attackers to exploit the system by sending a malformed AUTH SSL command which can cause the server to crash.
To mitigate risks from CVE-2014-1441, it is advised to update the Core FTP Server to build 515 or later.
Yes, a patch is provided in build 515 and later versions of Core FTP Server to address CVE-2014-1441.