An issue was discovered in tls_verify_crl in ProFTPD through 1.3.6b. A dereference of a NULL pointer may occur. This pointer is returned by the OpenSSL sk_X509_REVOKED_value() function when encountering an empty CRL installed by a system administrator. The dereference occurs when validating the certificate of a client connecting to the server in a TLS client/server mutual-authentication setup.
CVSS Details
- CVSS 3.1 Base Score: 4.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade proftpd-dfsg | Dec 2, 2019 | Dec 2, 2019 |
| Gentoo Linux | — | Upgrade net-ftp/proftpd. | Mar 17, 2020 | Nov 30, 2019 |
| Oracle Solaris | — | Upgrade service/network/ftp to version 1.3.6-11.4.19.0.1.2.0 on Solaris 11.4 | Jan 19, 2021 | Nov 30, 2019 |
| Proftp Proftpd | — | Update ProFTP ProFTPd to the latest version | Nov 6, 2025 | Nov 26, 2019 |
| Suse | — | Upgrade proftpd-langUpgrade proftpdUpgrade proftpd-radiusUpgrade proftpd-mysqlUpgrade proftpd-pgsqlUpgrade proftpd-sqliteUpgrade proftpd-develUpgrade proftpd-docUpgrade proftpd-ldap | Jan 15, 2020 | Nov 30, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub