HIGH
In ProFTPD 1.3.7, it is possible to corrupt the memory pool by interrupting the data transfer channel
Published Feb 20, 2020
8.8
HIGHCVSS 3.1
EPSS 12.14%
Description
In ProFTPD 1.3.7, it is possible to corrupt the memory pool by interrupting the data transfer channel. This triggers a use-after-free in alloc_pool in pool.c, and possible remote code execution.
Affected products
No data.
Configuration 2
OR
- 8.0
- 9.0
- 10.0
Configuration 3
OR
- 30
- 31
Configuration 4
OR
- 15.0
- 15.0
- 15.1
Configuration 5
AND
- n/a
Running on/with
- n/a
Configuration 6
AND
- < 3.0
Running on/with
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (12)
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00002.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2021/08/25/1 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2021/09/06/2 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-679335.pdf x_refsource_CONFIRMThird Party Advisory
- https://github.com/proftpd/proftpd/blob/master/RELEASE_NOTES x_refsource_CONFIRMRelease NotesThird Party Advisory
- https://github.com/proftpd/proftpd/issues/903 x_refsource_CONFIRMThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/02/msg00022.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/03/msg00002.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VCUPRYSJR7XOM3HQ6H5M4OGDU7OHCHBF/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XHO3S5WPRRP7VGKIAHLYQVEYW5HRYIJN/ vendor-advisoryx_refsource_FEDORA
- https://security.gentoo.org/glsa/202003-35 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://www.debian.org/security/2020/dsa-4635 vendor-advisoryx_refsource_DEBIANThird Party Advisory
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Feb 20, 2020
Updated Aug 4, 2024
Reserved Feb 19, 2020
Link CVE-2020-9273
CISA Vulnrichment
Updated n/a