ID

VAR-200812-0100


CVE

CVE-2008-5666


TITLE

Win FTP Server PASV Command Remote Denial of Service Vulnerability

Trust: 1.2

sources: CNVD: CNVD-2008-4886 // CNNVD: CNNVD-200812-379

DESCRIPTION

WinFTP FTP Server 2.3.0, when passive (aka PASV) mode is used, allows remote authenticated users to cause a denial of service via a sequence of FTP sessions that include an invalid "NLST -1" command. Win FTP Server is a professional Windows FTP server. If a remote attacker sends multiple login requests ending with a PASV command to Win FTP Server, it may cause the server to crash. Exploiting this issue allows remote attackers to crash the application, denying service to legitimate users. This issue affects Win FTP 2.0.2; other versions may also be vulnerable. ---------------------------------------------------------------------- Do you need accurate and reliable IDS / IPS / AV detection rules? Get in-depth vulnerability details: http://secunia.com/binary_analysis/sample_analysis/ ---------------------------------------------------------------------- TITLE: WinFTP "PASV" Denial of Service Vulnerability SECUNIA ADVISORY ID: SA32209 VERIFY ADVISORY: http://secunia.com/advisories/32209/ CRITICAL: Not critical IMPACT: DoS WHERE: >From remote SOFTWARE: WinFTP Server 2.x http://secunia.com/advisories/product/12923/ DESCRIPTION: A vulnerability has been discovered in WinFTP, which can be exploited by malicious users to cause a DoS (Denial of Service). The vulnerability is caused due to an error when handling the PASV command. The vulnerability is confirmed in version 2.3.0. Other versions may also be affected. SOLUTION: Grant access to trusted users only. PROVIDED AND/OR DISCOVERED BY: dmnt ORIGINAL ADVISORY: http://milw0rm.com/exploits/6717 ---------------------------------------------------------------------- About: This Advisory was delivered by Secunia as a free service to help everybody keeping their systems up to date against the latest vulnerabilities. Subscribe: http://secunia.com/advisories/secunia_security_advisories/ Definitions: (Criticality, Where etc.) http://secunia.com/advisories/about_secunia_advisories/ Please Note: Secunia recommends that you verify all advisories you receive by clicking the link. Secunia NEVER sends attached files with advisories. Secunia does not advise people to install third party patches, only use those supplied by the vendor. ---------------------------------------------------------------------- Unsubscribe: Secunia Security Advisories http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org ----------------------------------------------------------------------

Trust: 2.52

sources: NVD: CVE-2008-5666 // JVNDB: JVNDB-2008-006579 // CNVD: CNVD-2008-4886 // BID: 31686 // PACKETSTORM: 70859

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2008-4886

AFFECTED PRODUCTS

vendor:wftpservermodel:winftp ftp serverscope:eqversion:2.3.0

Trust: 1.6

vendor:wing ftpmodel:winftp ftp serverscope:eqversion:2.3.0

Trust: 0.8

vendor:nomodel: - scope: - version: -

Trust: 0.6

vendor:winmodel:ftp server win ftp serverscope:eqversion:2.3

Trust: 0.3

sources: CNVD: CNVD-2008-4886 // BID: 31686 // JVNDB: JVNDB-2008-006579 // CNNVD: CNNVD-200812-379 // NVD: CVE-2008-5666

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2008-5666
value: LOW

Trust: 1.0

NVD: CVE-2008-5666
value: LOW

Trust: 0.8

CNVD: CNVD-2008-4886
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-200812-379
value: LOW

Trust: 0.6

nvd@nist.gov: CVE-2008-5666
severity: LOW
baseScore: 3.5
vectorString: AV:N/AC:M/AU:S/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 6.8
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2008-4886
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2008-4886 // JVNDB: JVNDB-2008-006579 // CNNVD: CNNVD-200812-379 // NVD: CVE-2008-5666

PROBLEMTYPE DATA

problemtype:CWE-399

Trust: 1.8

sources: JVNDB: JVNDB-2008-006579 // NVD: CVE-2008-5666

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200812-379

TYPE

resource management error

Trust: 0.6

sources: CNNVD: CNNVD-200812-379

CONFIGURATIONS

sources: JVNDB: JVNDB-2008-006579

PATCH

title:Top Pageurl:http://www.wftpserver.com/

Trust: 0.8

sources: JVNDB: JVNDB-2008-006579

EXTERNAL IDS

db:NVDid:CVE-2008-5666

Trust: 2.7

db:SECUNIAid:32209

Trust: 1.8

db:EXPLOIT-DBid:6717

Trust: 1.7

db:VUPENid:ADV-2008-2801

Trust: 1.6

db:SECTRACKid:1021040

Trust: 1.6

db:SREASONid:4785

Trust: 1.6

db:BIDid:31686

Trust: 0.9

db:JVNDBid:JVNDB-2008-006579

Trust: 0.8

db:CNVDid:CNVD-2008-4886

Trust: 0.6

db:MILW0RMid:6717

Trust: 0.6

db:XFid:45806

Trust: 0.6

db:CNNVDid:CNNVD-200812-379

Trust: 0.6

db:PACKETSTORMid:70859

Trust: 0.1

sources: CNVD: CNVD-2008-4886 // BID: 31686 // JVNDB: JVNDB-2008-006579 // PACKETSTORM: 70859 // CNNVD: CNNVD-200812-379 // NVD: CVE-2008-5666

REFERENCES

url:http://www.securitytracker.com/id?1021040

Trust: 1.6

url:http://securityreason.com/securityalert/4785

Trust: 1.6

url:http://secunia.com/advisories/32209

Trust: 1.6

url:http://www.vupen.com/english/advisories/2008/2801

Trust: 1.0

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/45806

Trust: 1.0

url:https://www.exploit-db.com/exploits/6717

Trust: 1.0

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2008-5666

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2008-5666

Trust: 0.8

url:http://xforce.iss.net/xforce/xfdb/45806

Trust: 0.6

url:http://www.milw0rm.com/exploits/6717

Trust: 0.6

url:http://www.frsirt.com/english/advisories/2008/2801

Trust: 0.6

url:http://www.wftpserver.com/

Trust: 0.3

url:http://secunia.com/advisories/32209/

Trust: 0.1

url:http://secunia.com/advisories/product/12923/

Trust: 0.1

url:http://milw0rm.com/exploits/6717

Trust: 0.1

url:http://secunia.com/binary_analysis/sample_analysis/

Trust: 0.1

url:http://secunia.com/advisories/secunia_security_advisories/

Trust: 0.1

url:http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org

Trust: 0.1

url:http://secunia.com/advisories/about_secunia_advisories/

Trust: 0.1

sources: BID: 31686 // JVNDB: JVNDB-2008-006579 // PACKETSTORM: 70859 // CNNVD: CNNVD-200812-379 // NVD: CVE-2008-5666

CREDITS

dmnt

Trust: 0.9

sources: BID: 31686 // CNNVD: CNNVD-200812-379

SOURCES

db:CNVDid:CNVD-2008-4886
db:BIDid:31686
db:JVNDBid:JVNDB-2008-006579
db:PACKETSTORMid:70859
db:CNNVDid:CNNVD-200812-379
db:NVDid:CVE-2008-5666

LAST UPDATE DATE

2025-04-10T23:09:30.023000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2008-4886date:2014-01-24T00:00:00
db:BIDid:31686date:2008-12-19T20:11:00
db:JVNDBid:JVNDB-2008-006579date:2012-12-20T00:00:00
db:CNNVDid:CNNVD-200812-379date:2009-01-29T00:00:00
db:NVDid:CVE-2008-5666date:2025-04-09T00:30:58.490

SOURCES RELEASE DATE

db:CNVDid:CNVD-2008-4886date:2008-10-09T00:00:00
db:BIDid:31686date:2008-10-09T00:00:00
db:JVNDBid:JVNDB-2008-006579date:2012-12-20T00:00:00
db:PACKETSTORMid:70859date:2008-10-13T18:50:55
db:CNNVDid:CNNVD-200812-379date:2008-10-09T00:00:00
db:NVDid:CVE-2008-5666date:2008-12-19T01:52:02.483