Description
Filetto 1.0 FTP server contains a denial of service vulnerability in the FEAT command processing that allows attackers to crash the service. Attackers can send an oversized FEAT command with 11,008 bytes of repeated characters to trigger a buffer overflow and terminate the FTP service.
Problem types
Allocation of Resources Without Limits or Throttling
Product status
Credits
Alvaro J. Gene (Socket_0x03)
References
www.exploit-db.com/exploits/48503 (ExploitDB-48503)
www.utillyty.eu (Vendor Homepage)
sourceforge.net/projects/filetto (Software Project Repository)
www.vulncheck.com/advisories/filetto-feat-denial-of-service (VulnCheck Advisory: Filetto 1.0 - 'FEAT' Denial of Service)