CVE-2013-6809

Severity CVSS v4.0:
Pending analysis
Type:
CWE-134 Format String Vulnerability
Publication date:
13/12/2013
Last modified:
11/04/2025

Description

Format string vulnerability in the client in Tftpd32 before 4.50 allows remote servers to cause a denial of service (crash) or possibly execute arbitrary code via format string specifiers in the Remote File field.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:philippe_jounin:tftpd32:*:*:*:*:*:*:*:* 4.00 (including)
cpe:2.3:a:philippe_jounin:tftpd32:1.0:*:*:*:*:*:*:*
cpe:2.3:a:philippe_jounin:tftpd32:1.1:*:*:*:*:*:*:*
cpe:2.3:a:philippe_jounin:tftpd32:2.0:*:*:*:*:*:*:*
cpe:2.3:a:philippe_jounin:tftpd32:2.1:*:*:*:*:*:*:*
cpe:2.3:a:philippe_jounin:tftpd32:2.2:*:*:*:*:*:*:*
cpe:2.3:a:philippe_jounin:tftpd32:2.11:*:*:*:*:*:*:*
cpe:2.3:a:philippe_jounin:tftpd32:2.21:*:*:*:*:*:*:*
cpe:2.3:a:philippe_jounin:tftpd32:2.51:*:*:*:*:*:*:*
cpe:2.3:a:philippe_jounin:tftpd32:2.52:*:*:*:*:*:*:*
cpe:2.3:a:philippe_jounin:tftpd32:2.53:*:*:*:*:*:*:*
cpe:2.3:a:philippe_jounin:tftpd32:2.54:*:*:*:*:*:*:*
cpe:2.3:a:philippe_jounin:tftpd32:2.60:*:*:*:*:*:*:*
cpe:2.3:a:philippe_jounin:tftpd32:2.62:*:*:*:*:*:*:*
cpe:2.3:a:philippe_jounin:tftpd32:2.70:*:*:*:*:*:*:*