id: CVE-2008-5281 info: name: Titan FTP Server 6.05 DELE Command - Heap Overflow author: pussycat0x severity: critical description: | Titan FTP Server version 6.05 build 550 contains a heap overflow vulnerability when processing long DELE commands. Remote attackers can cause denial of service (daemon crash) or potentially execute arbitrary code by sending excessively long arguments to the DELE command. impact: | Unauthenticated attackers can send long DELE commands to trigger heap overflow, causing denial of service by crashing the FTP daemon or potentially executing arbitrary code on the server. remediation: | Update Titan FTP Server to a version newer than 6.05 build 550 that properly validates command length and prevents heap overflow vulnerabilities in the DELE command handler. classification: cvss-metrics: CVSS:2.0/AV:N/AC:L/Au:N/C:C/I:C/A:C cvss-score: 10 cve-id: CVE-2008-5281 cwe-id: CWE-119 epss-score: 0.06401 epss-percentile: 0.92942 cpe: cpe:2.3:a:south_river_technologies:titan_ftp_server:6.05:build_550:*:*:*:*:*:* metadata: verified: true max-request: 1 vendor: south_river_technologies product: titan_ftp_server shodan-query: product:"Titan FTP" tags: cve,cve2008,network,ftp,titan-ftp,tcp,passive,vuln tcp: - inputs: - data: 00000000 type: hex host: - "{{Hostname}}" port: 21 read-size: 1024 matchers: - type: dsl dsl: - "contains(raw, 'Titan')" - "contains(version, '6.05')" condition: and extractors: - type: regex group: 1 name: version regex: - "Titan FTP Server ([0-9.]+)" # digest: 4a0a004730450221009e8db585ea20a0a3b13c9f29d8de195fdfa1f0f3432bf002654750831d0c26720220574e9fc93cdd60ac4e11c8a0051c4db72b6a676e721d0beb5165c6cf3e19bd1c:922c64590222798bb761d5b6d8e72950