5
CVSSv2

CVE-2019-18217

Published: 21/10/2019 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 447
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

ProFTPD prior to 1.3.6b and 1.3.7rc prior to 1.3.7rc2 allows remote unauthenticated denial-of-service due to incorrect handling of overly long commands because main.c in a child process enters an infinite loop.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

proftpd proftpd 1.3.6

proftpd proftpd 1.3.7

proftpd proftpd

Vendor Advisories

Debian Bug report logs - #942831 CVE-2019-18217 Package: src:proftpd-dfsg; Maintainer for src:proftpd-dfsg is ProFTPD Maintainance Team <pkg-proftpd-maintainers@alioth-listsdebiannet>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Tue, 22 Oct 2019 08:09:09 UTC Severity: grave Tags: security Fixed in versi ...
Stephan Zeisberg discovered that missing input validation in ProFTPD, a FTP/SFTP/FTPS server, could result in denial of service via an infinite loop For the oldstable distribution (stretch), this problem has been fixed in version 135b-4+deb9u2 For the stable distribution (buster), this problem has been fixed in version 136-4+deb10u2 We recom ...