Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

T. Hauck Jana Server FTP Server PASV Mode Port Exhaustion Denial Of Service Vulnerability

Jana Server is a server for Microsoft Windows based systems. Jana Server provides a wide range of proxy servers, and a number of other services, including a FTP server.

An authenticated remote user may use the PASV command to force Jana Server to open a new connection. Reportedly, this connection does not time out, and will remain open indefinitely. A malicious user may make a number of PASV requests and exhaust all TCP ports on the vulnerable system.







 

Privacy Statement
Copyright 2008, SecurityFocus