PT-2007-1789 · Filezilla · Filezilla

Published

2007-01-18

·

Updated

2017-07-29

·

CVE-2007-0317

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: FileZilla versions prior to 3.0.0-beta5
Description: The issue is related to a format string vulnerability in the LogMessage function. This vulnerability can be exploited by remote attackers who send crafted arguments, potentially leading to a denial of service (application crash) and possibly allowing the execution of arbitrary code.
Recommendations: For versions prior to 3.0.0-beta5, update to version 3.0.0-beta5 or later to resolve the issue. As a temporary workaround, consider restricting access to the LogMessage function to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-0317

Affected Products

Filezilla