Описание
In ProFTPD 1.3.7, it is possible to corrupt the memory pool by interrupting the data transfer channel. This triggers a use-after-free in alloc_pool in pool.c, and possible remote code execution.
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | ignored | end of standard support, was needed |
| devel | not-affected | 1.3.6c-1 |
| eoan | ignored | end of life |
| esm-apps/bionic | needed | |
| esm-apps/focal | not-affected | 1.3.6c-1 |
| esm-apps/jammy | not-affected | 1.3.6c-1 |
| esm-apps/noble | not-affected | 1.3.6c-1 |
| esm-apps/xenial | needed | |
| esm-infra-legacy/trusty | DNE | |
| focal | not-affected | 1.3.6c-1 |
Показывать по
Ссылки на источники
EPSS
9 Critical
CVSS2
8.8 High
CVSS3
Связанные уязвимости
In ProFTPD 1.3.7, it is possible to corrupt the memory pool by interrupting the data transfer channel. This triggers a use-after-free in alloc_pool in pool.c, and possible remote code execution.
In ProFTPD 1.3.7, it is possible to corrupt the memory pool by interru ...
In ProFTPD 1.3.7, it is possible to corrupt the memory pool by interrupting the data transfer channel. This triggers a use-after-free in alloc_pool in pool.c, and possible remote code execution.
Уязвимость реализации функции alloc_pool FTP-сервера ProFTPD, позволяющая нарушителю выполнить произвольный код
EPSS
9 Critical
CVSS2
8.8 High
CVSS3