CVE-2013-6809

medium
Published 2013-12-13 ยท Modified 2026-04-29
CVSS v3
โ€”
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
5.0

Description

Format string vulnerability in the client in Tftpd32 before 4.50 allows remote servers to cause a denial of service (crash) or possibly execute arbitrary code via format string specifiers in the Remote File field.

Predictions

Exploit likelihood
20%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No mitigations published for this CVE yet.

The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ€” if you've already worked around this in production โ€” publish your fix to the community-verified tier.

โœš Propose a mitigation on Community โ†’ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here with source_tier=community-verified.

Application impact

VendorProductVersionsFixed
philippe_jounintftpd32{"endIncluding":"4.00"}
philippe_jounintftpd321.0
philippe_jounintftpd321.1
philippe_jounintftpd322.0
philippe_jounintftpd322.1
philippe_jounintftpd322.2
philippe_jounintftpd322.11
philippe_jounintftpd322.21
philippe_jounintftpd322.51
philippe_jounintftpd322.52
philippe_jounintftpd322.53
philippe_jounintftpd322.54
philippe_jounintftpd322.60
philippe_jounintftpd322.62
philippe_jounintftpd322.70
philippe_jounintftpd322.71
philippe_jounintftpd322.72
philippe_jounintftpd322.73
philippe_jounintftpd322.74
philippe_jounintftpd322.80
philippe_jounintftpd322.81
philippe_jounintftpd322.82
philippe_jounintftpd322.83
philippe_jounintftpd322.84
philippe_jounintftpd323.00
philippe_jounintftpd323.01
philippe_jounintftpd323.02
philippe_jounintftpd323.03
philippe_jounintftpd323.10
philippe_jounintftpd323.20
philippe_jounintftpd323.22
philippe_jounintftpd323.23
philippe_jounintftpd323.26
philippe_jounintftpd323.27
philippe_jounintftpd323.28
philippe_jounintftpd323.29
philippe_jounintftpd323.31
philippe_jounintftpd323.33
philippe_jounintftpd323.34
philippe_jounintftpd323.35
philippe_jounintftpd323.50
philippe_jounintftpd323.51

References

CWEs

CWE-134

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.