SunFTP Denial of Service Vulnerability

MEDIUM (5.0) No Patch (9169 days)

Threat Intelligence

Low Risk
EPSS Score: 0.69% chance of exploitation (percentile: 71%)
🔍 Detection Tools: None available in major open-source tools
⚔️ Exploit Availability: No public exploits found

How we test →

What is it?

SunFTP is a remote file transfer protocol server used by some organizations for secure data exchange. This vulnerability allows attackers to cause a denial of service by connecting to the server and disconnecting before sending a newline, effectively crashing the server.

Am I affected?

You're affected if you use SunFTP build 9(1). Check with: find / -name "sunftp*.bin" 2>/dev/null

Note: This is an older version of SunFTP, which might not be widely used or maintained. If you don't recognize the name, you're probably not affected.

Version info: Not specified in the advisory.

Affected Products

Sun Microsystems / SunFTP

How to fix

Upgrade to a newer version of SunFTP (e.g., 10(1) or later).
- Immediate mitigations:
- Disable remote file transfers until the issue is resolved.
- Monitor server logs for suspicious activity.