Advisories

Cobian Backup 11 Gravity 11.2.0.582 Local Denial of Service via Password Field

Go Back
severity
medium
date
Affecting
  • Cobian Backup Gravity 11.2.0.582

CWE
  • CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
CVSS
6.9
CVSS V4 Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Credit
Luis Martinez
Description
Cobian Backup 11 Gravity 11.2.0.582 contains a denial of service vulnerability in the FTP password input field that allows attackers to crash the application. Attackers can generate a specially crafted 800-byte buffer and paste it into the password field to trigger an application crash.