UNKNOWNCVE-2019-25654

Core FTP/SFTP Server 1.2 Denial of Service via Buffer Overflow

Platform

windows

Component

core-ftp-sftp-server

Core FTP/SFTP Server 1.2 contains a buffer overflow vulnerability that allows attackers to crash the service by supplying an excessively long string in the User domain field. Attackers can paste a malicious payload containing 7000 bytes of data into the domain configuration to trigger an application crash and deny service.

How to fix

Actualizar Core FTP/SFTP Server a una versión posterior a la 2-Build 673. Esto solucionará la vulnerabilidad de desbordamiento de búfer en el campo de dominio del usuario.

Monitor your dependencies automatically

Get notified when new vulnerabilities affect your projects. Free forever.

Start free