QPC Software QVT/Term Plus FTP server contains a flaw that may allow a remote denial of service. The issue is triggered when a long username and/or password (over 2000 characters) is sent to the server during the login process, which will result in an authentication error. The next time someone attempts to login the server will crash, and will result in loss of availability for the service.
Classification
Location:
Remote/Network Access Required
Attack Type:
Denial of Service,
Input Manipulation
Impact:
Loss of Availability
Exploit:
Exploit Available
Solution
Currently, there are no known upgrades, patches, or workarounds available to correct this issue.