ID

VAR-200109-0058


CVE

CVE-2001-0646


TITLE

Maxum Rumpus FTP Server service denial vulnerability

Trust: 0.6

sources: CNNVD: CNNVD-200109-118

DESCRIPTION

Maxum Rumpus FTP Server 1.3.3 and 2.0.3 dev 3 allows a remote attacker to perform a denial of service (hang) by creating a directory name of a specific length. Rumpus FTP Server is an implementation for MacOS which allows file-sharing across TCP/IP connections. It is possible to log in remotely to the server and shut down the service by making a directory with a name that is 65 characters long. Users must be authenticated to engage this attack

Trust: 1.17

sources: NVD: CVE-2001-0646 // BID: 2716

AFFECTED PRODUCTS

vendor:maxummodel:rumpus ftp serverscope:eqversion:1.3.4

Trust: 1.9

vendor:maxummodel:rumpus ftp serverscope:eqversion:1.3.2

Trust: 1.9

vendor:maxummodel:rumpus ftp serverscope:eqversion:2.0.3dev

Trust: 1.6

vendor:maxummodel:rumpus ftp server devscope:eqversion:2.0.3

Trust: 0.3

vendor:maxummodel:rumpus ftp serverscope:neversion:1.3.6

Trust: 0.3

vendor:maxummodel:rumpus ftp serverscope:neversion:1.3.5

Trust: 0.3

sources: BID: 2716 // CNNVD: CNNVD-200109-118 // NVD: CVE-2001-0646

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2001-0646
value: MEDIUM

Trust: 1.0

CNNVD: CNNVD-200109-118
value: MEDIUM

Trust: 0.6

nvd@nist.gov: CVE-2001-0646
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

sources: CNNVD: CNNVD-200109-118 // NVD: CVE-2001-0646

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

sources: NVD: CVE-2001-0646

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200109-118

TYPE

unknown

Trust: 0.6

sources: CNNVD: CNNVD-200109-118

EXTERNAL IDS

db:BIDid:2716

Trust: 1.9

db:NVDid:CVE-2001-0646

Trust: 1.6

db:XFid:6542

Trust: 0.6

db:BUGTRAQid:20010515 RUMPUS FTP DOS

Trust: 0.6

db:CNNVDid:CNNVD-200109-118

Trust: 0.6

sources: BID: 2716 // CNNVD: CNNVD-200109-118 // NVD: CVE-2001-0646

REFERENCES

url:http://www.securityfocus.com/bid/2716

Trust: 1.6

url:http://www.securityfocus.com/archive/1/184751

Trust: 1.6

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/6542

Trust: 1.0

url:http://xforce.iss.net/static/6542.php

Trust: 0.6

url:http://www.maxum.com/rumpus/

Trust: 0.3

sources: BID: 2716 // CNNVD: CNNVD-200109-118 // NVD: CVE-2001-0646

CREDITS

Jass Seljamaa <jass@email.isp.ee> posted this vulnerability to BugTraq on May 15th, 2001.

Trust: 0.3

sources: BID: 2716

SOURCES

db:BIDid:2716
db:CNNVDid:CNNVD-200109-118
db:NVDid:CVE-2001-0646

LAST UPDATE DATE

2025-04-03T22:33:18.993000+00:00


SOURCES UPDATE DATE

db:BIDid:2716date:2001-05-15T00:00:00
db:CNNVDid:CNNVD-200109-118date:2006-09-05T00:00:00
db:NVDid:CVE-2001-0646date:2025-04-03T01:03:51.193

SOURCES RELEASE DATE

db:BIDid:2716date:2001-05-15T00:00:00
db:CNNVDid:CNNVD-200109-118date:2001-09-20T00:00:00
db:NVDid:CVE-2001-0646date:2001-09-20T04:00:00