CVE-2020-9273Use After Free in Proftpd

CWE-416Use After Free6 documents6 sources
Severity
8.8HIGHNVD
EPSS
68.9%
top 1.36%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 20
Latest updateMay 24

Description

In ProFTPD 1.3.7, it is possible to corrupt the memory pool by interrupting the data transfer channel. This triggers a use-after-free in alloc_pool in pool.c, and possible remote code execution.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages4 packages

Also affects: Debian Linux 10.0, 8.0, 9.0, Fedora 30, 31

🔴Vulnerability Details

3
GHSA
GHSA-j879-hg9w-v5qv: In ProFTPD 12022-05-24
OSV
CVE-2020-9273: In ProFTPD 12020-02-20
CVEList
CVE-2020-9273: In ProFTPD 12020-02-20

📋Vendor Advisories

1
Debian
CVE-2020-9273: proftpd-dfsg - In ProFTPD 1.3.7, it is possible to corrupt the memory pool by interrupting the ...2020

💬Community

1
Bugzilla
CVE-2020-9273 proftpd: use-after-free in alloc_pool in pool.c2020-03-02
CVE-2020-9273 — Use After Free in Proftpd | cvebase