Serv-U < 9.0.0.1

medium Nessus Plugin ID 41980

Synopsis

The remote FTP server is affected by multiple vulnerabilities.

Description

The installed version of Serv-U is earlier than 9.0.0.1 and as such is reportedly affected by following issues :

- Provided 'SITE SET' command is enabled, an authorized user may be able to crash the remote FTP server by sending a specially crafted 'SITE SET TRANSFERPROGRESS ON' command.

- An unprivileged user may be able to view all drives and virtual paths for drive '\'.

Solution

Upgrade to Serv-U version 9.0.0.1 or later.

See Also

https://support.solarwinds.com/Success_Center/Serv-U_Managed_File_Transfer_Serv-U_FTP_Server/Serv-U_Documentation/release_notes

Plugin Details

Severity: Medium

ID: 41980

File Name: servu_9_0_0_1.nasl

Version: 1.12

Type: remote

Family: FTP

Published: 10/5/2009

Updated: 4/11/2022

Configuration: Enable thorough checks

Supported Sensors: Nessus

Risk Information

CVSS v2

Risk Factor: Medium

Base Score: 4.3

Temporal Score: 3.2

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Information

CPE: cpe:/a:serv-u:serv-u

Required KB Items: ftp/servu

Exploit Ease: No known exploits are available

Patch Publication Date: 9/29/2009

Vulnerability Publication Date: 9/29/2009

Reference Information

BID: 36585

SECUNIA: 36873