Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jwr6-3j75-vrwj

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The administration web interface in NetWin SurgeFTP 2.3a2 and earlier allows remote attackers to cause a denial of service (daemon crash) via a large integer in the Content-Length HTTP header, which triggers a NULL pointer dereference when memory allocation fails.

The administration web interface in NetWin SurgeFTP 2.3a2 and earlier allows remote attackers to cause a denial of service (daemon crash) via a large integer in the Content-Length HTTP header, which triggers a NULL pointer dereference when memory allocation fails.

EPSS

Процентиль: 91%
0.06983
Низкий

Дефекты

CWE-119

Связанные уязвимости

nvd
почти 18 лет назад

The administration web interface in NetWin SurgeFTP 2.3a2 and earlier allows remote attackers to cause a denial of service (daemon crash) via a large integer in the Content-Length HTTP header, which triggers a NULL pointer dereference when memory allocation fails.

EPSS

Процентиль: 91%
0.06983
Низкий

Дефекты

CWE-119