ID

VAR-200612-0786


TITLE

Dream FTP Server PORT Command Denial of Service Vulnerability

Trust: 0.6

sources: CNVD: CNVD-2006-9310

DESCRIPTION

Dream FTP Server is a multi-threaded ftp server. Dream FTP Server has a vulnerability in handling user requests, and a remote attacker could exploit this vulnerability to perform a denial of service attack on the server. A remote attacker can cause a denial of service by sending a PORT command with an invalid parameter to the Dream FTP Server. Exploiting this issue allows remote attackers to crash the application, denying further service to legitimate users. It is not known at this time if this issue can be exploited to execute arbitrary code; this BID will be updated as further information becomes available. This issue affects version 1.0.2; other versions may also be vulnerable

Trust: 0.81

sources: CNVD: CNVD-2006-9310 // BID: 21700

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2006-9310

AFFECTED PRODUCTS

vendor:nomodel: - scope: - version: -

Trust: 0.6

vendor:bolintechmodel:dream ftp serverscope:eqversion:1.0.2

Trust: 0.3

sources: CNVD: CNVD-2006-9310 // BID: 21700

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2006-9310
value: MEDIUM

Trust: 0.6

CNVD: CNVD-2006-9310
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2006-9310

THREAT TYPE

network

Trust: 0.3

sources: BID: 21700

TYPE

Failure to Handle Exceptional Conditions

Trust: 0.3

sources: BID: 21700

EXTERNAL IDS

db:BIDid:21700

Trust: 0.9

db:CNVDid:CNVD-2006-9310

Trust: 0.6

sources: CNVD: CNVD-2006-9310 // BID: 21700

REFERENCES

url:http://www.bolintech.com/index.htm

Trust: 0.3

sources: BID: 21700

CREDITS

InTeL is credited with the discovery of this vulnerability.

Trust: 0.3

sources: BID: 21700

SOURCES

db:CNVDid:CNVD-2006-9310
db:BIDid:21700

LAST UPDATE DATE

2022-05-17T02:01:36.065000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2006-9310date:2014-01-24T00:00:00
db:BIDid:21700date:2006-12-21T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2006-9310date:2006-12-21T00:00:00
db:BIDid:21700date:2006-12-21T00:00:00