Published: 21/10/2019 Updated: 27/10/2019
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

ProFTPD prior to 1.3.6b and 1.3.7rc prior to 1.3.7rc2 allows remote unauthenticated denial-of-service due to incorrect handling of overly long commands because main.c in a child process enters an infinite loop.

Vulnerability Trend

Affected Products

Vendor Product Versions
ProftpdProftpd1.3.5, 1.3.6, 1.3.7

Vendor Advisories

Debian Bug report logs - #942831 CVE-2019-18217 Package: src:proftpd-dfsg; Maintainer for src:proftpd-dfsg is ProFTPD Maintainance Team <pkg-proftpd-maintainers@alioth-listsdebiannet>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Tue, 22 Oct 2019 08:09:09 UTC Severity: grave Tags: security Fixed in versi ...
Stephan Zeisberg discovered that missing input validation in ProFTPD, a FTP/SFTP/FTPS server, could result in denial of service via an infinite loop For the oldstable distribution (stretch), this problem has been fixed in version 135b-4+deb9u2 For the stable distribution (buster), this problem has been fixed in version 136-4+deb10u2 We recom ...
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 # SSA-940889: Vulnerabilities in the embedded FTP server of SIMATIC CP 1543-1 Publication Date: 2020-02-11 Last Update: 2020-02-11 Current Version: 10 CVSS v31 Base Score: 98 SUMMARY ======= The latest update for SIMATIC CP 1543-1 contains two fixes for vulnerabili ...

Mailing Lists

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4559-1 security () debian org wwwdebianorg/security/ Moritz Muehlenhoff November 05, 2019 wwwdebianorg/security/faq ...