FTP.Command.CWD.DoS

Alias/esCommand.CWD.DoS
Release DateSep 11, 2006
SeverityHigh
ImpactAn attacker can cause Denial-of-Service on a target system
Description

It indicates a Denial-of-Service (DoS) vulnerability in Ipswitch WS FTP Server.

A remote attacker can trigger the vulnerability by passing a specially-crafted FTP Change Working Directory (CWD) command to a target system.

Affected ProductsAny unprotected Ipswitch WS FTP Server 1.0.1, 1.0.2, 1.0.3, 1.0.4, 1.0.5, or 2.0 is vulernable to the attack.
Recommended Actions

Upgrade the server to the latest non-vulnerable version.

Common Vulnerabilities and Exposures (CVE)http://cve.mitre.org/cgi-bin/cvename.cgi?name=1999-0082
Reference/shttp://www.securityfocus.com/bid/9237 (BugTraq)
Reference: VID-12568