CVE-2013-4742: Buffer Overflow
Published Aug 9, 2013
·Updated
Buffer overflow in NetWin SurgeFTP before 23d2 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long string within the authentication request.
Affected Software
16 affected components
Netwin SurgeFTP<=2.3b1
Netwin SurgeFTP=2.0c
Netwin SurgeFTP=2.0d
Netwin SurgeFTP=2.0e
Netwin SurgeFTP=2.0f
Netwin SurgeFTP=2.2k1
Netwin SurgeFTP=2.2k3
Netwin SurgeFTP=2.2m1
Netwin SurgeFTP=2.3a1
Netwin SurgeFTP=2.3a2
Netwin SurgeFTP=2.3a6
Netwin SurgeFTP=2.3a7
Netwin SurgeFTP=2.3a8
Netwin SurgeFTP=2.3a9
Netwin SurgeFTP=2.3a10
Netwin SurgeFTP=2.3a12
Event History
Aug 9, 2013
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-4742?
CVE-2013-4742 has a high severity rating due to its potential to cause a denial of service and execute arbitrary code.
2
How do I fix CVE-2013-4742?
To fix CVE-2013-4742, you should upgrade NetWin SurgeFTP to version 23d2 or later.
3
Which versions of NetWin SurgeFTP are affected by CVE-2013-4742?
CVE-2013-4742 affects all NetWin SurgeFTP versions prior to 23d2, including 2.3b1 and earlier versions.
4
What type of attack does CVE-2013-4742 facilitate?
CVE-2013-4742 facilitates a buffer overflow attack that can lead to denial of service or remote code execution.
5
Is CVE-2013-4742 a critical vulnerability?
Yes, CVE-2013-4742 is considered critical as it allows remote attackers to exploit the flaw without requiring authentication.