Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j63h-gfj3-rm54

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

NetSarang XFTP Client 6.0149 and earlier version contains a buffer overflow vulnerability caused by improper boundary checks when copying file name from an attacker controlled FTP server. That leads attacker to execute arbitrary code by sending a crafted filename.

NetSarang XFTP Client 6.0149 and earlier version contains a buffer overflow vulnerability caused by improper boundary checks when copying file name from an attacker controlled FTP server. That leads attacker to execute arbitrary code by sending a crafted filename.

EPSS

Процентиль: 77%
0.01028
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-119
CWE-120

Связанные уязвимости

CVSS3: 9.8
nvd
больше 6 лет назад

NetSarang XFTP Client 6.0149 and earlier version contains a buffer overflow vulnerability caused by improper boundary checks when copying file name from an attacker controlled FTP server. That leads attacker to execute arbitrary code by sending a crafted filename.

EPSS

Процентиль: 77%
0.01028
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-119
CWE-120