Executive brief
Serv-U is a popular FTP server used to share files over a network. A vulnerability in version 2.5 allows an attacker to remotely crash the server by sending specially crafted commands. This results in a denial of service, preventing legitimate users from accessing or transferring files until the service is manually restarted.
Technical details
A buffer overflow vulnerability exists in Serv-U FTP server version 2.5 and potentially earlier versions. The flaw is triggered when the server processes FTP commands that take arguments, such as CWD (Change Working Directory) or LS (List), containing strings of 155 characters or more. An authenticated remote attacker can exploit this by sending a long argument to these commands, leading to a service crash (Denial of Service). The vendor released a beta patch shortly after disclosure to address the boundary checking issue.
Affected products
- Rhinosoft (formerly Cat Soft) Serv-U 2.5 and earlier
Timeline
- 1997-07-01: disclosed: Initial vulnerability disclosure date
- 1999-05-03: other: Public report on NTBUGTRAQ mailing list
- 1999-05-04: patched: Vendor released beta fix following public disclosure