Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2020-9273

Опубликовано: 20 фев. 2020
Источник: ubuntu
Приоритет: medium
EPSS Средний
CVSS2: 9
CVSS3: 8.8

Описание

In ProFTPD 1.3.7, it is possible to corrupt the memory pool by interrupting the data transfer channel. This triggers a use-after-free in alloc_pool in pool.c, and possible remote code execution.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needed
devel

not-affected

1.3.6c-1
eoan

ignored

end of life
esm-apps/bionic

needed

esm-apps/focal

not-affected

1.3.6c-1
esm-apps/jammy

not-affected

1.3.6c-1
esm-apps/noble

not-affected

1.3.6c-1
esm-apps/xenial

needed

esm-infra-legacy/trusty

DNE

focal

not-affected

1.3.6c-1

Показывать по

EPSS

Процентиль: 98%
0.6675
Средний

9 Critical

CVSS2

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
nvd
почти 6 лет назад

In ProFTPD 1.3.7, it is possible to corrupt the memory pool by interrupting the data transfer channel. This triggers a use-after-free in alloc_pool in pool.c, and possible remote code execution.

CVSS3: 8.8
debian
почти 6 лет назад

In ProFTPD 1.3.7, it is possible to corrupt the memory pool by interru ...

github
больше 3 лет назад

In ProFTPD 1.3.7, it is possible to corrupt the memory pool by interrupting the data transfer channel. This triggers a use-after-free in alloc_pool in pool.c, and possible remote code execution.

CVSS3: 8.8
fstec
почти 6 лет назад

Уязвимость реализации функции alloc_pool FTP-сервера ProFTPD, позволяющая нарушителю выполнить произвольный код

suse-cvrf
больше 5 лет назад

Security update for proftpd

EPSS

Процентиль: 98%
0.6675
Средний

9 Critical

CVSS2

8.8 High

CVSS3