Use-after-free vulnerability in the Response API in ProFTPD before 1.3.3g allows remote authenticated users to execute arbitrary code via vectors involving an error that occurs after an FTP data transfer.
CVSS Details
- CVSS 3.1 Base Score: 8.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade proftpd-dfsg | Jul 30, 2024 | Dec 6, 2011 |
| Gentoo Linux | — | Upgrade net-ftp/proftpd. | Oct 30, 2017 | Dec 6, 2011 |
| Oracle Solaris | — | Upgrade service/network/ftp to version 1.3.3.0.7-0.175.0.3.0.4.0 on Solaris 11.0 | May 29, 2017 | Dec 6, 2011 |
| Proftp Proftpd | — | Update ProFTP ProFTPd to the latest version | Nov 6, 2025 | Dec 6, 2011 |
| Suse | — | Upgrade proftpd-sqliteUpgrade proftpd-debugsourceUpgrade proftpd-develUpgrade proftpd-sqlite-debuginfoUpgrade proftpd-ldap-debuginfoUpgrade proftpd-radius-debuginfoUpgrade proftpd-ldapUpgrade proftpd-pgsqlUpgrade proftpd-pgsql-debuginfoUpgrade proftpd-docUpgrade proftpdUpgrade proftpd-mysql-debuginfoUpgrade proftpd-mysqlUpgrade proftpd-debuginfoUpgrade proftpd-radius | Dec 12, 2013 | Dec 6, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub