CVE-2011-10029
Solar FTP Server fails to properly handle format strings passed to the USER command. When a specially crafted string containing format specifiers is sent, the server crashes due to a read access violation in the __output_1() function of sfsservice.exe. This results in a denial of service (DoS) condition.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.7
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 48.84%
- CWE
- CWE-134
- Published
- 2025-08-20
- Last modified
- 2026-05-15
Affected products
- Flexbyte Software Solar FTP Server
- Flexbyte Software Solar FTP Server
Weakness type
Related vulnerabilities
- CVE-2024-23113 — A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.
- CVE-2012-10055 — ComSndFTP v1.3.7 Beta USER Format String RCE
- CVE-2023-35086 — ASUS RT-AX56U V2 & RT-AC86U - Format String -1
- CVE-2020-3118 — Cisco IOS XR Software Cisco Discovery Protocol Format String Vulnerability
- CVE-2022-26674 — ASUS RT-AX88U - Format String
- CVE-2022-34747 — A format string vulnerability in Zyxel NAS326 firmware versions prior to V5.21(AAZF.12)C0 could allow an attacker to ach
- CVE-2021-41193 — Use of Externally-Controlled Format String in wire-avs
- CVE-2023-35087 — ASUS RT-AX56U V2 & RT-AC86U - Format String - 2