Nessus Plugin #14537

Plugin Index

Note: This file has been created from a downloaded version of the Nessus Plugins from http://www.nessus.org/. Therefore, the information here can be outdated.

[GLSA-200407-04] Pure-FTPd: Potential DoS when maximum connections is reached

Family:
Gentoo Local Security Checks
Category:
infos
Copyright:
(C) 2004 Michel Arboi
Summary:
Pure-FTPd: Potential DoS when maximum connections is reached
Version:
$Revision: 1.1 $
Cve_id:
-
Bugtraq_id:
-
Xrefs:
GLSA:200407-04
Description:
The remote host is affected by the vulnerability described in GLSA-200407-04
(Pure-FTPd: Potential DoS when maximum connections is reached)


Pure-FTPd contains a bug in the accept_client function handling the setup
of new connections.

Impact

When the maximum number of connections is reached an attacker could exploit
this vulnerability to perform a Denial of Service attack.

Workaround

There is no known workaround at this time. All users are encouraged to
upgrade to the latest available version.

References:
http://www.pureftpd.org


Solution:
All Pure-FTPd users should upgrade to the latest stable version:
# emerge sync
# emerge -pv ">=net-ftp/pure-ftpd-1.0.18-r1"
# emerge ">=net-ftp/pure-ftpd-1.0.18-r1"


Risk Factor : Medium
Generiert am 27.04.2005 um 18:49:54 Uhr.