ProFTPD before 1.3.6b and 1.3.7rc before 1.3.7rc2 allows remote unauthenticated denial-of-service due to incorrect handling of overly long commands because main.c in a child process enters an infinite loop.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade proftpd-dfsg | Oct 29, 2019 | Oct 21, 2019 |
| Gentoo Linux | — | Upgrade net-ftp/proftpd. | Mar 17, 2020 | Oct 21, 2019 |
| Oracle Solaris | — | Upgrade security/kerberos-5/kdc to version 1.16.1.0-11.4.16.0.1.3.0 on Solaris 11.4Upgrade library/libtasn1 to version 4.13-11.4.16.0.1.3.0 on Solaris 11.4Upgrade security/kerberos-5 to version 1.16.1.0-11.4.16.0.1.3.0 on Solaris 11.4Upgrade service/network/ftp to version 1.3.6-11.4.16.0.1.3.0 on Solaris 11.4 | Dec 18, 2019 | Oct 21, 2019 |
| Proftp Proftpd | — | Update ProFTP ProFTPd to the latest version | Nov 6, 2025 | Oct 21, 2019 |
| Suse | — | Upgrade proftpd-radiusUpgrade proftpdUpgrade proftpd-develUpgrade proftpd-docUpgrade proftpd-langUpgrade proftpd-mysqlUpgrade proftpd-ldapUpgrade proftpd-sqliteUpgrade proftpd-pgsql | Jan 15, 2020 | Oct 21, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub