cbcvebase.
CVE-2020-9273
published 2020-02-20

CVE-2020-9273: In ProFTPD 1.3.7, it is possible to corrupt the memory pool by interrupting the data transfer channel. This triggers a use-after-free in alloc_pool in pool.c…

high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
In ProFTPD 1.3.7, it is possible to corrupt the memory pool by interrupting the data transfer channel. This triggers a use-after-free in alloc_pool in pool.c, and possible remote code execution.

Affected

10 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debiandebian_linux
debianproftpd-dfsg< proftpd-dfsg 1.3.6c-2 (bookworm)proftpd-dfsg 1.3.6c-2 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
opensusebackports_sle
opensuseleap
proftpdproftpd
siemenssimatic_net_cp_1543-1_firmware< 3.03.0

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH