Description
WebSSH for iOS 14.16.10 contains a denial of service vulnerability in the mashREPL tool that allows attackers to crash the application by pasting malformed input. Attackers can trigger the vulnerability by copying a 300-character buffer of repeated 'A' characters into the mashREPL input field, causing the application to crash.
Problem types
Improper Validation of Specified Quantity in Input
Product status
Credits
Luis Martinez
References
www.exploit-db.com/exploits/49883 (ExploitDB-49883)
apps.apple.com/mx/app/webssh-ssh-client/id497714887 (WebSSH iOS App Store Page)
www.vulncheck.com/...bssh-for-ios-mashrepl-denial-of-service (VulnCheck Advisory: WebSSH for iOS 14.16.10 - 'mashREPL' Denial of Service)