vendor:
Navicat
by:
Rafael Alfaro
7.5
CVSS
HIGH
Denial of Service (DoS) Local
400
CWE
Product Name: Navicat
Affected Version From: 12.0.0
Affected Version To: 12.0.29
Patch Exists: NO
Related CWE:
CPE: a:navicat:navicat:12.0.29
Platforms Tested: Windows 7 x64 en, Windows 10 Home x64 es
2018
Navicat 12.0.29 – ‘SSH’ Denial of Service (PoC)
The exploit allows an attacker to cause a Denial of Service (DoS) by running a python code which writes a large buffer to a file, causing the Navicat application to crash when it tries to open the file.
Mitigation:
Update to the latest version of Navicat that includes a patch for this vulnerability.