Format string vulnerability in XM Easy Personal FTP Server 5.2.1 allows remote attackers to cause a denial of service (application crash) via format string specifiers in the USER command or certain other available or nonexistent commands. NOTE: It was later reported that 5.3.0 is also vulnerable.
The product uses a function that accepts a format string as an argument, but the format string originates from an external source.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Xm_easy_personal_ftp_server | Dxmsoft | 5.2.1 (including) | 5.2.1 (including) |
Xm_easy_personal_ftp_server | Dxmsoft | 5.3 (including) | 5.3 (including) |