CVE Database
/

CVE-2008-1052

Back to search

CVE-2008-1052

Published: Feb 27, 2008

Modified: Aug 7, 2024

PUBLISHED

Description

The administration web interface in NetWin SurgeFTP 2.3a2 and earlier allows remote attackers to cause a denial of service (daemon crash) via a large integer in the Content-Length HTTP header, which triggers a NULL pointer dereference when memory allocation fails.

VendorProductVersions

n/a

n/a

affected
n/a

References

20080225 NULL pointer in SurgeFTP 2.3a2
mailing-list
x_refsource_BUGTRAQ
29096
third-party-advisory
x_refsource_SECUNIA
surgeftp-contentlength-dos(40843)
vdb-entry
x_refsource_XF
3704
third-party-advisory
x_refsource_SREASON
27993
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now