CVE-2019-25654: Core FTP/SFTP Server 1.2 Denial of Service via Buffer Overflow
Core FTP/SFTP Server 1.2 contains a buffer overflow vulnerability that allows attackers to crash the service by supplying an excessively long string in the User domain field. Attackers can paste a malicious payload containing 7000 bytes of data into the domain configuration to trigger an application crash and deny service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-25654?
CVE-2019-25654 is classified as a Denial of Service vulnerability due to the buffer overflow issue.
How do I fix CVE-2019-25654?
To mitigate CVE-2019-25654, upgrade Core FTP/SFTP Server to a version higher than 1.2 where the vulnerability is addressed.
Who is affected by CVE-2019-25654?
CVE-2019-25654 affects users of Core FTP/SFTP Server version 1.2.
What type of attack does CVE-2019-25654 enable?
CVE-2019-25654 enables attackers to perform a Denial of Service attack by crashing the server.
Is there any known exploit for CVE-2019-25654?
Yes, there is a known exploit that demonstrates how to exploit the buffer overflow vulnerability in CVE-2019-25654.