vendor:
FileZilla
by:
3unnym00n
5.5
CVSS
MEDIUM
Denial of Service
20
CWE
Product Name: FileZilla
Affected Version From: 3.11.0.2
Affected Version To: 3.11.0.2
Patch Exists: NO
Related CWE: CVE-2015-1251
CPE: a:filezilla_project:filezilla:3.11.0.2
Platforms Tested: Windows 7, Windows XP
2015
filezilla 3.11.0.2 sftp module denial of service vulnerability
SFTP module for FileZilla, based on Putty's PSFTP component, is vulnerable to a denial of service attack. When performing the SSH DH group exchange old style, if the server sends a malformed DH group exchange reply, it can cause the FileZilla component to crash.
Mitigation:
Update to a version of FileZilla that is not affected by this vulnerability.