CVE-2020-36617 - CVE House
Back to Database
Status published Medium CVE-2020-36617

ewxrjk sftpserver parse.c sftp_parse_path uninitialized pointer

Vulnerability Description

A vulnerability was found in ewxrjk sftpserver. It has been declared as problematic. Affected by this vulnerability is the function sftp_parse_path of the file parse.c. The manipulation leads to uninitialized pointer. The real existence of this vulnerability is still doubted at the moment. The name of the patch is bf4032f34832ee11d79aa60a226cc018e7ec5eed. It is recommended to apply a patch to fix this issue. The identifier VDB-216205 was assigned to this vulnerability. NOTE: In some deployment models this would be a vulnerability. README specifically warns about avoiding such deployment models.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-36617

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

sftpserver
Vulnerable Versions:
Unknown

Timeline

Official Publish: December 18th, 2022
Last Modified: April 15th, 2025
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L

Weaknesses (CWE)