Summary
The remote ProFTPd server is as old or older than 1.2.10
It is possible to determine which user names are valid on the remote host based on timing analysis attack of the login procedure.
An attacker may use this flaw to set up a list of valid usernames for a more efficient brute-force attack against the remote host.
Solution
Upgrade to a newer version
Severity
Classification
-
CVE CVE-2004-1602 -
CVSS Base Score: 5.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
Related Vulnerabilities
- Core FTP Server 'Type' Command Remote Denial of Service Vulnerability
- XM Easy Personal FTP Server 'LIST' And 'NLST' Command DoS Vulnerability
- wu-ftpd ls -W memory exhaustion
- vsftpd '__tzfile_read()' Function Heap Based Buffer Overflow Vulnerability
- NcFTPD Symbolic Link Information Disclosure Vulnerability