id: CVE-2004-0437 info: name: Titan FTP Server 3.01 - DoS via LIST Command Disconnection author: pussycat0x severity: medium description: | Titan FTP Server version 3.01 build 163 (and possibly other older versions) contains a vulnerability where disconnecting during a LIST -L command may crash the daemon. Remote attackers can cause denial of service by initiating a LIST -L command and then abruptly disconnecting, leading to server instability. impact: | Attackers can cause denial of service by initiating LIST -L commands and disconnecting abruptly, leading to Titan FTP Server crashes and service interruptions. remediation: | Upgrade Titan FTP Server to a version later than 3.01 build 163 that properly handles abrupt client disconnections. reference: - http://marc.info/?l=bugtraq&m=108378048513596&w=2 - https://exchange.xforce.ibmcloud.com/vulnerabilities/16057 classification: cvss-metrics: CVSS:2.0/AV:N/AC:L/Au:N/C:N/I:N/A:P cvss-score: 5 cve-id: CVE-2004-0437 epss-score: 0.07672 epss-percentile: 0.93953 cpe: cpe:2.3:a:south_river_technologies:titan_ftp_server:3.01_build_163:*:*:*:*:*:*:* metadata: max-request: 1 vendor: south_river_technologies product: titan_ftp_server shodan-query: product:"Titan ftpd" tags: cve,cve2004,network,ftp,titan-ftp,tcp,passive,vuln tcp: - inputs: - data: 00000000 type: hex host: - "{{Hostname}}" port: 21 read-size: 1024 matchers: - type: dsl dsl: - "contains(raw, 'Titan')" - "contains(version, '3.01')" condition: and extractors: - type: regex group: 1 name: version regex: - "Titan FTP Server ([0-9.]+)" # digest: 490a0046304402205c4e6d50332a13da3316f3f898cc1da47bcab02b489a2849f253951bd63f79d3022042cf1c7cc83f11e7f1930d99a5586b5c9e6c0ed28707cb23f899ab692863c976:922c64590222798bb761d5b6d8e72950