Serv-U FTP Server before 6.1.0.4 allows attackers to cause a denial of service (crash) via (1) malformed packets and possibly other unspecified issues with unknown impact and attack vectors including (2) use of "~" in a pathname, and (3) memory consumption of the daemon. NOTE: it is not clear whether items (2) and above are vulnerabilities.
2005-11-02T23:02:00.000
2025-04-03T01:03:51.193
Deferred
CVSSv2: 5.0 (MEDIUM)
AV:N/AC:L/Au:N/C:N/I:N/A:P
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | solarwinds | serv-u_file_server | ≤ 6.1.0.1 | Yes |
Application | solarwinds | serv-u_file_server | 3.0.0.16 | Yes |
Application | solarwinds | serv-u_file_server | 3.0.0.17 | Yes |
Application | solarwinds | serv-u_file_server | 3.1.0.0 | Yes |
Application | solarwinds | serv-u_file_server | 3.1.0.1 | Yes |
Application | solarwinds | serv-u_file_server | 3.1.0.3 | Yes |
Application | solarwinds | serv-u_file_server | 4.0.0.4 | Yes |
Application | solarwinds | serv-u_file_server | 4.1.0.0 | Yes |
Application | solarwinds | serv-u_file_server | 4.1.0.3 | Yes |
Application | solarwinds | serv-u_file_server | 5.0.0.0 | Yes |
Application | solarwinds | serv-u_file_server | 5.0.0.4 | Yes |
Application | solarwinds | serv-u_file_server | 5.0.0.9 | Yes |
Application | solarwinds | serv-u_file_server | 5.0.0.11 | Yes |
Application | solarwinds | serv-u_file_server | 5.1.0.0 | Yes |
Application | solarwinds | serv-u_file_server | 5.2.0.0 | Yes |
Application | solarwinds | serv-u_file_server | 5.2.0.1 | Yes |
Application | solarwinds | serv-u_file_server | 6.0.0.0 | Yes |
Application | solarwinds | serv-u_file_server | 6.0.0.1 | Yes |
Application | solarwinds | serv-u_file_server | 6.0.0.2 | Yes |
Application | solarwinds | serv-u_file_server | 6.1.0.0 | Yes |