id: CVE-2006-6565 info: name: FileZilla Server < 0.9.22 - DoS via Wildcard Commands author: pussycat0x severity: medium description: | FileZilla Server versions prior to 0.9.22 are vulnerable to remote denial of service (crash) when processing wildcard arguments to LIST/NLST commands, malformed PORT commands, or other malformed commands. This leads to NULL pointer dereference that can crash the server. impact: | Authenticated attackers can cause denial of service by sending malformed wildcard arguments in LIST/NLST commands or malformed PORT commands, triggering NULL pointer dereference that crashes the FTP server. remediation: | Update FileZilla Server to version 0.9.22 or later that properly validates command arguments and prevents NULL pointer dereference vulnerabilities. reference: - http://sourceforge.net/project/shownotes.php?release_id=470364&group_id=21558 - http://www.vupen.com/english/advisories/2006/4937 - https://exchange.xforce.ibmcloud.com/vulnerabilities/30853 classification: cvss-metrics: CVSS:2.0/AV:N/AC:L/Au:S/C:N/I:N/A:P cvss-score: 4 cve-id: CVE-2006-6565 cwe-id: CWE-476 epss-score: 0.71504 epss-percentile: 0.9935 cpe: cpe:2.3:a:filezilla-project:filezilla_server:*:*:*:*:*:*:*:* metadata: verified: true max-request: 1 vendor: filezilla-project product: filezilla_server shodan-query: product:"FileZilla" tags: cve,cve2006,network,ftp,filezilla,tcp,passive,vuln tcp: - inputs: - data: 00000000 type: hex host: - "{{Hostname}}" port: 21 read-size: 1024 matchers: - type: dsl dsl: - "contains(raw, 'FileZilla')" - "compare_versions(version, '< 0.9.22')" condition: and extractors: - type: regex group: 1 name: version regex: - "FileZilla Server version ([0-9.]+)" # digest: 4b0a00483046022100acb035db026dd755ee8513c7657c079060e901deb98d1037031fa0bd19e4fa0d022100ee354f8ae17c3251d63f0a7e98b216eab8f3f12492e72740d4ff5eb14249567b:922c64590222798bb761d5b6d8e72950