Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-19269

Опубликовано: 30 нояб. 2019
Источник: nvd
CVSS3: 4.9
CVSS2: 4
EPSS Низкий

Описание

An issue was discovered in tls_verify_crl in ProFTPD through 1.3.6b. A dereference of a NULL pointer may occur. This pointer is returned by the OpenSSL sk_X509_REVOKED_value() function when encountering an empty CRL installed by a system administrator. The dereference occurs when validating the certificate of a client connecting to the server in a TLS client/server mutual-authentication setup.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:proftpd:proftpd:*:*:*:*:*:*:*:*
Версия до 1.3.5e (включая)
cpe:2.3:a:proftpd:proftpd:1.3.6:-:*:*:*:*:*:*
cpe:2.3:a:proftpd:proftpd:1.3.6:alpha:*:*:*:*:*:*
cpe:2.3:a:proftpd:proftpd:1.3.6:beta:*:*:*:*:*:*
cpe:2.3:a:proftpd:proftpd:1.3.6:rc1:*:*:*:*:*:*
cpe:2.3:a:proftpd:proftpd:1.3.6:rc2:*:*:*:*:*:*
cpe:2.3:a:proftpd:proftpd:1.3.6:rc3:*:*:*:*:*:*
cpe:2.3:a:proftpd:proftpd:1.3.6:rc4:*:*:*:*:*:*
Конфигурация 2

Одно из

cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*
Конфигурация 3
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

EPSS

Процентиль: 82%
0.0178
Низкий

4.9 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-476

Связанные уязвимости

CVSS3: 4.9
ubuntu
около 6 лет назад

An issue was discovered in tls_verify_crl in ProFTPD through 1.3.6b. A dereference of a NULL pointer may occur. This pointer is returned by the OpenSSL sk_X509_REVOKED_value() function when encountering an empty CRL installed by a system administrator. The dereference occurs when validating the certificate of a client connecting to the server in a TLS client/server mutual-authentication setup.

CVSS3: 4.9
debian
около 6 лет назад

An issue was discovered in tls_verify_crl in ProFTPD through 1.3.6b. A ...

github
больше 3 лет назад

An issue was discovered in tls_verify_crl in ProFTPD through 1.3.6b. A dereference of a NULL pointer may occur. This pointer is returned by the OpenSSL sk_X509_REVOKED_value() function when encountering an empty CRL installed by a system administrator. The dereference occurs when validating the certificate of a client connecting to the server in a TLS client/server mutual-authentication setup.

CVSS3: 7.5
fstec
около 6 лет назад

Уязвимость FTP-сервера ProFTPD, связанная с разыменованием нулевого указателя, позволяющая нарушителю вызвать отказ в обслуживании

suse-cvrf
почти 6 лет назад

Security update for proftpd

EPSS

Процентиль: 82%
0.0178
Низкий

4.9 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-476