CVE-2014-1441: Race Condition
Published May 2, 2014
·Updated
Core FTP Server 1.2 before build 515 allows remote attackers to cause a denial of service (reachable assertion and crash) via an AUTH SSL command with malformed data, as demonstrated by pressing the enter key twice.
Affected Software
1 affected component
CoreFTP Core Ftp=1.2
Event History
May 2, 2014
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Data Sourced
via NVD·01:59 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-1441?
CVE-2014-1441 is classified as a denial of service vulnerability.
2
What software versions are affected by CVE-2014-1441?
CVE-2014-1441 affects Core FTP Server versions prior to 1.2 build 515.
3
How does CVE-2014-1441 allow attackers to exploit the system?
CVE-2014-1441 allows attackers to exploit the system by sending a malformed AUTH SSL command which can cause the server to crash.
4
How can I mitigate the risks associated with CVE-2014-1441?
To mitigate risks from CVE-2014-1441, it is advised to update the Core FTP Server to build 515 or later.
5
Is there a patch available for CVE-2014-1441?
Yes, a patch is provided in build 515 and later versions of Core FTP Server to address CVE-2014-1441.