WFTPD Pro Server 3.21 Release 1 allocates memory for a command until a 0Ah byte (newline) is sent, which allows local users to cause a denial of service (CPU consumption) by continuing to send a long command that does not contain a newline.
Software | From | Fixed in |
---|---|---|
texas_imperial_software / wftpd | 3.0 | 3.0.x |
texas_imperial_software / wftpd | 3.0_0r3 | 3.0_0r3.x |
texas_imperial_software / wftpd | 3.0_0r4 | 3.0_0r4.x |
texas_imperial_software / wftpd | 3.0_0r5 | 3.0_0r5.x |
texas_imperial_software / wftpd | 3.10_r1 | 3.10_r1.x |
texas_imperial_software / wftpd | 3.20 | 3.20.x |
texas_imperial_software / wftpd | 3.21 | 3.21.x |
texas_imperial_software / wftpd | pro_3.10_r1 | pro_3.10_r1.x |
texas_imperial_software / wftpd | pro_3.20 | pro_3.20.x |
texas_imperial_software / wftpd | pro_3.21 | pro_3.21.x |