PT-2022-9013 · Unknown · Ewxrjk Sftpserver

Published

2022-12-18

·

Updated

2024-08-04

·

CVE-2020-36617

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ewxrjk sftpserver (affected versions not specified)
Description A vulnerability was found in the ewxrjk sftpserver, affecting the function sftp parse path of the file parse.c. The manipulation leads to an uninitialized pointer. The real existence of this vulnerability is still doubted at the moment. In some deployment models, this would be considered a vulnerability, and the README specifically warns about avoiding such deployment models.
Recommendations To fix this issue, it is recommended to apply a patch. The name of the patch is bf4032f34832ee11d79aa60a226cc018e7ec5eed. As a temporary workaround, consider disabling the sftp parse path function until a patch is available.

Fix

Use of Uninitialized Resource

Weakness Enumeration

Related Identifiers

CVE-2020-36617

Affected Products

Ewxrjk Sftpserver