Use-after-free vulnerability in the Response API in ProFTPD before 1.3.3g allows remote authenticated users to execute arbitrary code via vectors involving an error that occurs after an FTP data transfer.
CVSS Details
- CVSS 3.1 Base Score: 8.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade proftpd-dfsg | Jul 30, 2024 | Dec 6, 2011 |
| Gentoo Linux | — | Upgrade net-ftp/proftpd. | Oct 30, 2017 | Dec 6, 2011 |
| Oracle Solaris | — | Upgrade service/network/ftp to version 1.3.3.0.7-0.175.0.3.0.4.0 on Solaris 11.0 | May 29, 2017 | Dec 6, 2011 |
| Proftp Proftpd | — | Update ProFTP ProFTPd to the latest version | Nov 6, 2025 | Dec 6, 2011 |
| Suse | — | Upgrade proftpd-docUpgrade proftpd-pgsql-debuginfoUpgrade proftpd-mysqlUpgrade proftpd-mysql-debuginfoUpgrade proftpd-pgsqlUpgrade proftpdUpgrade proftpd-debuginfoUpgrade proftpd-radiusUpgrade proftpd-develUpgrade proftpd-ldap-debuginfoUpgrade proftpd-radius-debuginfoUpgrade proftpd-ldapUpgrade proftpd-debugsourceUpgrade proftpd-sqliteUpgrade proftpd-sqlite-debuginfo | Dec 12, 2013 | Dec 6, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub