Описание
make_ftp_cmd in main.c in ProFTPD before 1.3.8a has a one-byte out-of-bounds read, and daemon crash, because of mishandling of quote/backslash semantics.
Пакеты
Пакет | Статус | Версия исправления | Релиз | Тип |
---|---|---|---|---|
proftpd-dfsg | fixed | 1.3.8.a+dfsg-1 | package | |
proftpd-dfsg | fixed | 1.3.8+dfsg-4+deb12u3 | bookworm | package |
proftpd-dfsg | no-dsa | buster | package |
Примечания
https://github.com/proftpd/proftpd/issues/1683
https://github.com/proftpd/proftpd/commit/1376d8ccc0966d1ce9a1c76b32c6a9ca61bbe67f (v1.3.9rc1)
https://github.com/proftpd/proftpd/commit/97bbe68363ccf2de0c07f67170ec64a8b4d62592 (v1.3.8a)
Связанные уязвимости
make_ftp_cmd in main.c in ProFTPD before 1.3.8a has a one-byte out-of-bounds read, and daemon crash, because of mishandling of quote/backslash semantics.
make_ftp_cmd in main.c in ProFTPD before 1.3.8a has a one-byte out-of-bounds read, and daemon crash, because of mishandling of quote/backslash semantics.
make_ftp_cmd in main.c in ProFTPD before 1.3.8a has a one-byte out-of-bounds read, and daemon crash, because of mishandling of quote/backslash semantics.
Уязвимость функции make_ftp_cmd компонента main.c FTP-сервера ProFTPD, позволяющая нарушителю вызвать отказ в обслуживании