CVE-2019-12815Improper Handling of Exceptional Conditions in Proftpd

Severity
9.8CRITICALNVD
CNA10.0OSV10.0
EPSS
78.8%
top 0.95%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 19
Latest updateMay 24

Description

An arbitrary file copy vulnerability in mod_copy in ProFTPD up to 1.3.5b allows for remote code execution and information disclosure without authentication, a related issue to CVE-2015-3306.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

Also affects: Debian Linux 10.0, 8.0, 9.0, Fedora 29, 30

Patches

🔴Vulnerability Details

3
GHSA
GHSA-f989-xw5v-4w5p: An arbitrary file copy vulnerability in mod_copy in ProFTPD up to 12022-05-24
OSV
CVE-2019-12815: An arbitrary file copy vulnerability in mod_copy in ProFTPD up to 12019-07-19
CVEList
CVE-2019-12815: An arbitrary file copy vulnerability in mod_copy in ProFTPD up to 12019-07-19

📋Vendor Advisories

1
Debian
CVE-2019-12815: proftpd-dfsg - An arbitrary file copy vulnerability in mod_copy in ProFTPD up to 1.3.5b allows ...2019

💬Community

3
Bugzilla
CVE-2019-12815 proftpd: file copy vulnerability in mod_copy allows for remote code execution [epel-all]2019-07-23
Bugzilla
CVE-2019-12815 proftpd: file copy vulnerability in mod_copy allows for remote code execution [fedora-all]2019-07-23
Bugzilla
CVE-2019-12815 proftpd: file copy vulnerability in mod_copy allows for remote code execution2019-07-23
CVE-2019-12815 — Proftpd vulnerability | cvebase