VYPR
Critical severity9.8NVD Advisory· Published Oct 10, 2019· Updated Jun 17, 2026

CVE-2019-17320

CVE-2019-17320

Description

NetSarang XFTP Client 6.0149 and earlier version contains a buffer overflow vulnerability caused by improper boundary checks when copying file name from an attacker controlled FTP server. That leads attacker to execute arbitrary code by sending a crafted filename.

Affected products

3
  • Netsarang/Xftp2 versions
    cpe:2.3:a:netsarang:xftp:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:netsarang:xftp:*:*:*:*:*:*:*:*range: <=6.0149
    • (no CPE)range: 6.0149 and earlier
  • Range: <=6.0149

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.