vendor:
FileZilla
by:
Mr Winst0n
5.5
CVSS
MEDIUM
Denial of Service (DoS)
399
CWE
Product Name: FileZilla
Affected Version From: 3.40.0
Affected Version To: 3.40.0
Patch Exists: NO
Related CWE:
CPE: a:filezilla_project:filezilla:3.40.0
Platforms Tested: Kali linux x86_64
2019
FileZilla 3.40.0 – “Local search” Denial of Service (PoC)
The exploit consists of a python script that creates a file with a specific payload and causes FileZilla 3.40.0 to crash when the payload is pasted in the "Search directory" field of the "Local search" feature.
Mitigation:
Update to a patched version of FileZilla.