MEDIUM · 4.0

CVE-2006-6564

FileZilla Server before 0.9.22 allows remote attackers to cause a denial of service (crash) via a malformed argument to the STOR command, which results in a NULL pointer dereference. NOTE: CVE analys...

Vulnerability Description

FileZilla Server before 0.9.22 allows remote attackers to cause a denial of service (crash) via a malformed argument to the STOR command, which results in a NULL pointer dereference. NOTE: CVE analysis suggests that the problem might be due to a malformed PORT command.

CVSS Score

4.0

MEDIUM

AV:N/AC:L/Au:S/C:N/I:N/A:P
Confidentiality
NONE
Integrity
NONE
Availability
PARTIAL

Affected Products

VendorProductVersions
FilezillaFilezilla<= 0.9.21

References

FAQ

What is CVE-2006-6564?

CVE-2006-6564 is a vulnerability with a CVSS score of 4.0 (MEDIUM). FileZilla Server before 0.9.22 allows remote attackers to cause a denial of service (crash) via a malformed argument to the STOR command, which results in a NULL pointer dereference. NOTE: CVE analys...

How severe is CVE-2006-6564?

CVE-2006-6564 has been rated MEDIUM with a CVSS base score of 4.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2006-6564?

Check the references section above for vendor advisories and patch information. Affected products include: Filezilla Filezilla.