Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f3r7-pgvq-gjh2

Опубликовано: 20 авг. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.7

Описание

Solar FTP Server fails to properly handle format strings passed to the USER command. When a specially crafted string containing format specifiers is sent, the server crashes due to a read access violation in the __output_1() function of sfsservice.exe. This results in a denial of service (DoS) condition.

Solar FTP Server fails to properly handle format strings passed to the USER command. When a specially crafted string containing format specifiers is sent, the server crashes due to a read access violation in the __output_1() function of sfsservice.exe. This results in a denial of service (DoS) condition.

EPSS

Процентиль: 98%
0.58597
Средний

8.7 High

CVSS4

Дефекты

CWE-134

Связанные уязвимости

nvd
6 месяцев назад

Solar FTP Server fails to properly handle format strings passed to the USER command. When a specially crafted string containing format specifiers is sent, the server crashes due to a read access violation in the __output_1() function of sfsservice.exe. This results in a denial of service (DoS) condition.

EPSS

Процентиль: 98%
0.58597
Средний

8.7 High

CVSS4

Дефекты

CWE-134