BulletProof FTP Server 2019.0.0.50 zawiera podatność denial of service w polu DNS Address, którą lokalni atakujący mogą wykorzystać do zawieszenia aplikacji, podając zbyt długi ciąg znaków. Atakujący mogą włączyć opcję DNS Address w ustawieniach firewall i wkleić bufor 700 bajtów, aby spowodować crash po wywołaniu funkcji Test.
▸ Pokaż oryginał (EN)
BulletProof FTP Server 2019.0.0.50 contains a denial of service vulnerability in the DNS Address field that allows local attackers to crash the application by supplying an excessively long string. Attackers can enable the DNS Address option in the Firewall settings and paste a buffer of 700 bytes to trigger a crash when the Test function is invoked.
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XBpftpserver Bulletproof Ftp Server
APPBpftpserver2019.0.0.50
Powiązane podatności
BulletProof FTP Server 2019.0.0.50 zawiera lukę typu denial of service w interfejsie konfiguracji SMTP, pozwal...
BulletProof FTP Server 2019.0.0.50 zawiera podatność DoS w parametrze konfiguracyjnym Storage-Path, która pozw...