CVE-2018-20658: Input Validation
Published Jan 2, 2019
·Updated
The server in Core FTP 2.0 build 653 on 32-bit platforms allows remote attackers to cause a denial of service (daemon crash) via a crafted XRMD command.
Affected Software
1 affected component
CoreFTP Core Ftp=2.0
Event History
Jan 2, 2019
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-20658?
CVE-2018-20658 is considered a medium severity vulnerability as it can lead to a denial of service due to a server crash.
2
How do I fix CVE-2018-20658?
To fix CVE-2018-20658, update Core FTP to the latest version where the issue has been addressed.
3
What systems are affected by CVE-2018-20658?
CVE-2018-20658 affects Core FTP version 2.0 running on 32-bit platforms.
4
What type of attack is associated with CVE-2018-20658?
CVE-2018-20658 is associated with a remote denial of service attack triggered by a crafted XRMD command.
5
Is there a workaround for CVE-2018-20658?
There are no specific workarounds documented for CVE-2018-20658 other than upgrading to a safer version.