English
The Internet threat alert status is currently normal. At present, no major epidemics or other serious incidents have been recorded by Kaspersky Lab’s monitoring service. Internet threat level: 1

Wing FTP Server ZIP Command Processing Denial of Service Vulnerability


Secunia ID

SA50919

CVE-ID

CVE-2012-4729

Release Date

10 Oct 2012

Last Change

19 Nov 2012

Criticality

Less Critical

Solution Status

Vendor Patch

Software

Wing FTP Server 4.x

Where

From remote

Impact
DoS (Denial of Service)

This includes vulnerabilities ranging from excessive resource consumption (e.g. causing a system to use a lot of memory) to crashing an application or an entire system.

Description

Anil Pazvant has reported a vulnerability in Wing FTP Server, which can be exploited by malicious users to cause a DoS (Denial of Service).

The vulnerability is caused due to an error when handling multiple ZIP commands and can be exploited to crash the service.

The vulnerability is reported in versions prior to 4.1.1.

Solution

Update to version 4.1.1.

Reported by

Anil Pazvant

Original Advisory

Wing FTP:
http://www.wftpserver.com/serverhistory.htm

Anil Pazvant:
http://archives.neohapsis.com/archives/bugtraq/2012-10/0050.html