HIGH
ProFTPD 1.3.7 has an out-of-bounds (OOB) read vulnerability in mod_cap via the cap_text.c cap_to_text function
Published Feb 20, 2020
7.5
HIGHCVSS 3.1
EPSS 2.11%
Description
ProFTPD 1.3.7 has an out-of-bounds (OOB) read vulnerability in mod_cap via the cap_text.c cap_to_text function.
Affected products
No data.
Configuration 2
AND
- < 3.0
Running on/with
- n/a
Configuration 3
AND
- n/a
Running on/with
- n/a
Configuration 4
OR
- 15.0
- 15.0
- 15.1
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00002.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-679335.pdf x_refsource_CONFIRMThird Party Advisory
- https://github.com/proftpd/proftpd/blob/master/RELEASE_NOTES x_refsource_CONFIRMRelease NotesThird Party Advisory
- https://github.com/proftpd/proftpd/issues/902 x_refsource_CONFIRMIssue TrackingPatchThird Party Advisory
- https://security.gentoo.org/glsa/202003-35 vendor-advisoryx_refsource_GENTOOThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00002.html | vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory | |
| https://cert-portal.siemens.com/productcert/pdf/ssa-679335.pdf | x_refsource_CONFIRMThird Party Advisory | |
| https://github.com/proftpd/proftpd/blob/master/RELEASE_NOTES | x_refsource_CONFIRMRelease NotesThird Party Advisory | |
| https://github.com/proftpd/proftpd/issues/902 | x_refsource_CONFIRMIssue TrackingPatchThird Party Advisory | |
| https://security.gentoo.org/glsa/202003-35 | vendor-advisoryx_refsource_GENTOOThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Feb 20, 2020
Updated Aug 4, 2024
Reserved Feb 19, 2020
Link CVE-2020-9272
CISA Vulnrichment
Updated n/a