HIGH · 8.5

CVE-2007-3768

The mirror mechanism in SurgeFTP 2.3a1 allows user-assisted, remote FTP servers to cause a denial of service (restart) via a malformed response to a PASV command.

Vulnerability Description

The mirror mechanism in SurgeFTP 2.3a1 allows user-assisted, remote FTP servers to cause a denial of service (restart) via a malformed response to a PASV command.

CVSS Score

8.5

HIGH

AV:N/AC:L/Au:N/C:N/I:P/A:C
Confidentiality
NONE
Integrity
PARTIAL
Availability
COMPLETE

Affected Products

VendorProductVersions
NetwinSurgeftp<= 2.3a1

References

FAQ

What is CVE-2007-3768?

CVE-2007-3768 is a vulnerability with a CVSS score of 8.5 (HIGH). The mirror mechanism in SurgeFTP 2.3a1 allows user-assisted, remote FTP servers to cause a denial of service (restart) via a malformed response to a PASV command.

How severe is CVE-2007-3768?

CVE-2007-3768 has been rated HIGH with a CVSS base score of 8.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2007-3768?

Check the references section above for vendor advisories and patch information. Affected products include: Netwin Surgeftp.