Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Xlight FTP Server < 3.9.5 Pre-Auth Heap Buffer Overflow via SSH Parser
Vulnerability Description
Xlight FTP Server before 3.9.5 contains a pre-authentication heap buffer overflow vulnerability that allows remote unauthenticated attackers to write past the end of a heap buffer by sending a malformed SSH client identification string. A logic error in the recv loop's termination condition uses an incorrect OR operator where an AND operator is required, enabling exploitation on any SSH or SFTP connection before authentication occurs.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
堆缓冲区溢出
Vulnerability Title
Xlight FTP Server 缓冲区错误漏洞
Vulnerability Description
xlight ftp server是xlight ftp server个人开发者的一款轻量级FTP服务器软件。 Xlight FTP Server 3.9.5之前版本存在缓冲区错误漏洞,该漏洞源于预认证堆缓冲区溢出,由于recv循环终止条件逻辑错误(使用了错误的OR运算符),导致远程未认证攻击者通过发送畸形SSH客户端标识字符串,可写入堆缓冲区之外。
CVSS Information
N/A
Vulnerability Type
N/A