CVE-2019-25683: FileZilla 3.40.0 Denial of Service via Local Search
FileZilla 3.40.0 contains a denial of service vulnerability in the local search functionality that allows local attackers to crash the application by supplying a malformed path string. Attackers can trigger the crash by entering a crafted path containing 384 'A' characters followed by 'BBBB' and 'CCCC' sequences in the search directory field and initiating a local search operation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-25683?
CVE-2019-25683 is classified as a denial of service vulnerability that can crash the application.
How do I fix CVE-2019-25683?
To fix CVE-2019-25683, update FileZilla to a version later than 3.40.0.
Who is affected by CVE-2019-25683?
CVE-2019-25683 affects users of FileZilla version 3.40.0.
What type of attack does CVE-2019-25683 involve?
CVE-2019-25683 involves a local attacker exploiting a malformed path string.
What is the impact of CVE-2019-25683?
The impact of CVE-2019-25683 is the crashing of the FileZilla application, resulting in denial of service.