CVE-2020-9273
published 2020-02-20CVE-2020-9273: In ProFTPD 1.3.7, it is possible to corrupt the memory pool by interrupting the data transfer channel. This triggers a use-after-free in alloc_pool in pool.c…
PriorityP259high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
12.04%
95.7th percentile
In ProFTPD 1.3.7, it is possible to corrupt the memory pool by interrupting the data transfer channel. This triggers a use-after-free in alloc_pool in pool.c, and possible remote code execution.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | proftpd-dfsg | < proftpd-dfsg 1.3.6c-2 (bookworm) | proftpd-dfsg 1.3.6c-2 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| opensuse | backports_sle | — | — |
| opensuse | leap | — | — |
| proftpd | proftpd | — | — |
| siemens | simatic_net_cp_1543-1_firmware | < 3.0 | 3.0 |
Detection & IOCsextracted from sources · hover to see the quote
- →The vulnerability is triggered by interrupting the data transfer channel in ProFTPD, causing a use-after-free in alloc_pool in pool.c — monitor for abrupt/abnormal FTP data channel disconnections followed by continued FTP command activity on the same session. ↗
- →Restrict and monitor FTP control/data traffic on Port 21/TCP; unexpected interruptions of data transfers from low-privileged authenticated users should be treated as suspicious. ↗
- →Track the upstream issue report for PoC details and indicators: https://github.com/proftpd/proftpd/issues/903 ↗
- ·Exploitation requires a low-privileged (authenticated) user; unauthenticated exploitation is not indicated by the CVSS vector (PR:L). ↗
- ·The embedded FTP server on affected Siemens SIMATIC CP devices is deactivated in the default configuration; attack surface only exists if FTP has been explicitly enabled. ↗
- ·No known public exploits specifically target this vulnerability as of the advisory date. ↗
- ·The vulnerability affects ProFTPD 1.3.7; fixed versions include 1.3.6c (Debian), 1.3.5e (EPEL-7 backport), and 1.3.3g (EPEL-6 backport) — ensure version checks account for these backported fixes. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
osv8.8HIGH
vendor_debian8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SIMATIC CP (Update A)
cisa_ics·2021-08-10·CVSS 7.5
[HIGH] Siemens SIMATIC CP (Update A)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SIMATIC CP (Update A)
Last RevisedJune 16, 2022
Alert CodeICSA-21-222-07
## 1. EXECUTIVE SUMMARY
- CVSS v3 8.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC
- Vulnerabilities: Out-of-Bounds Read, Use After Free
## 2. UPDATE INFORMATION
This updated advisory is a follow-up to the original advisory titled ICSA-21-222-07 Siemens SIMATIC NET CP that was published August 10, 2021, on the ICS webpage on cisa.gov/ics.
## 3. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow a remote attacker to a
Debian
CVE-2020-9273: proftpd-dfsg - In ProFTPD 1.3.7, it is possible to corrupt the memory pool by interrupting the ...
vendor_debian·2020·CVSS 8.8
CVE-2020-9273 [HIGH] CVE-2020-9273: proftpd-dfsg - In ProFTPD 1.3.7, it is possible to corrupt the memory pool by interrupting the ...
In ProFTPD 1.3.7, it is possible to corrupt the memory pool by interrupting the data transfer channel. This triggers a use-after-free in alloc_pool in pool.c, and possible remote code execution.
Scope: local
bookworm: resolved (fixed in 1.3.6c-2)
bullseye: resolved (fixed in 1.3.6c-2)
forky: resolved (fixed in 1.3.6c-2)
sid: resolved (fixed in 1.3.6c-2)
trixie: resolved (fixed in 1.3.6c-2)
GHSA
GHSA-j879-hg9w-v5qv: In ProFTPD 1
ghsa_unreviewed·2022-05-24
CVE-2020-9273 [HIGH] CWE-416 GHSA-j879-hg9w-v5qv: In ProFTPD 1
In ProFTPD 1.3.7, it is possible to corrupt the memory pool by interrupting the data transfer channel. This triggers a use-after-free in alloc_pool in pool.c, and possible remote code execution.
OSV
CVE-2020-9273: In ProFTPD 1
osv·2020-02-20·CVSS 8.8
CVE-2020-9273 [HIGH] CVE-2020-9273: In ProFTPD 1
In ProFTPD 1.3.7, it is possible to corrupt the memory pool by interrupting the data transfer channel. This triggers a use-after-free in alloc_pool in pool.c, and possible remote code execution.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00002.htmlhttp://www.openwall.com/lists/oss-security/2021/08/25/1http://www.openwall.com/lists/oss-security/2021/09/06/2https://cert-portal.siemens.com/productcert/pdf/ssa-679335.pdfhttps://github.com/proftpd/proftpd/blob/master/RELEASE_NOTEShttps://github.com/proftpd/proftpd/issues/903https://lists.debian.org/debian-lts-announce/2020/02/msg00022.htmlhttps://lists.debian.org/debian-lts-announce/2020/03/msg00002.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VCUPRYSJR7XOM3HQ6H5M4OGDU7OHCHBF/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XHO3S5WPRRP7VGKIAHLYQVEYW5HRYIJN/https://security.gentoo.org/glsa/202003-35https://www.debian.org/security/2020/dsa-4635http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00002.htmlhttp://www.openwall.com/lists/oss-security/2021/08/25/1http://www.openwall.com/lists/oss-security/2021/09/06/2https://cert-portal.siemens.com/productcert/pdf/ssa-679335.pdfhttps://github.com/proftpd/proftpd/blob/master/RELEASE_NOTEShttps://github.com/proftpd/proftpd/issues/903https://lists.debian.org/debian-lts-announce/2020/02/msg00022.htmlhttps://lists.debian.org/debian-lts-announce/2020/03/msg00002.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VCUPRYSJR7XOM3HQ6H5M4OGDU7OHCHBF/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XHO3S5WPRRP7VGKIAHLYQVEYW5HRYIJN/https://security.gentoo.org/glsa/202003-35https://www.debian.org/security/2020/dsa-4635
2020-02-20
Published