| |||||||||||||
| Test Kennung: | 1.3.6.1.4.1.25623.1.0.801614 |
| Kategorie: | FTP |
| Titel: | pyftpdlib FTP Server Denial of Service Vulnerability |
| Zusammenfassung: | Check for the version of pyftpdlib |
| Beschreibung: | Overview: This host is running pyftpdlib FTP server and is prone to Denial of Service vulnerability. Vulnerability Insight: The flaw is due to race condition in the FTPHandler class, which allows remote attackers to cause a denial of service by establishing and then immediately closing a TCP connection, leading to the accept function having an unexpected return value of None. Impact: Successful exploitation will allow attacker to cause a denial of service. Impact Level: Application Affected Software/OS: ftpserver.py in pyftpdlib before 0.5.1 Fix: Upgrade to pyftpdlib version 0.5.2 or later, For updates refer to http://code.google.com/p/pyftpdlib/downloads/list References: http://code.google.com/p/pyftpdlib/issues/detail?id=91 http://code.google.com/p/pyftpdlib/source/detail?r=439 http://code.google.com/p/pyftpdlib/source/browse/trunk/HISTORY |
| Querverweis: |
Common Vulnerability Exposure (CVE) ID: CVE-2009-5010 http://www.openwall.com/lists/oss-security/2010/09/09/6 http://www.openwall.com/lists/oss-security/2010/09/11/2 http://www.openwall.com/lists/oss-security/2010/09/22/3 http://www.openwall.com/lists/oss-security/2010/09/24/3 http://bugs.python.org/issue6706 https://bugs.launchpad.net/zodb/+bug/135108 |
| Copyright | Copyright (C) 2010 Greenbone Networks GmbH |
| Dies ist nur einer von 32582 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus. Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten. |
|