ProFTPD 1.3.7 has an out-of-bounds (OOB) read vulnerability in mod_cap via the cap_text.c cap_to_text function.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade proftpd-dfsg | Jul 30, 2024 | Feb 20, 2020 |
| Gentoo Linux | — | Upgrade net-ftp/proftpd. | Mar 17, 2020 | Feb 20, 2020 |
| Proftp Proftpd | — | Update ProFTP ProFTPd to the latest version | Nov 6, 2025 | Feb 20, 2020 |
| Suse | — | Upgrade proftpd-pgsqlUpgrade proftpd-radiusUpgrade proftpd-sqliteUpgrade proftpdUpgrade proftpd-langUpgrade proftpd-ldapUpgrade proftpd-docUpgrade proftpd-develUpgrade proftpd-mysql | Mar 3, 2020 | Feb 20, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub