In ProFTPD 1.3.7, it is possible to corrupt the memory pool by interrupting the data transfer channel. This triggers a use-after-free in alloc_pool in pool.c, and possible remote code execution.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade proftpd-dfsg | Feb 24, 2020 | Feb 20, 2020 |
| Gentoo Linux | — | Upgrade net-ftp/proftpd. | Mar 17, 2020 | Feb 20, 2020 |
| Oracle Solaris | — | Upgrade service/network/ftp to version 1.3.6-11.4.21.0.1.69.0 on Solaris 11.4 | Jan 19, 2021 | Feb 20, 2020 |
| Proftp Proftpd | — | Update ProFTP ProFTPd to the latest version | Nov 6, 2025 | Feb 20, 2020 |
| Suse | — | Upgrade proftpd-mysqlUpgrade proftpd-radiusUpgrade proftpd-docUpgrade proftpdUpgrade proftpd-sqliteUpgrade proftpd-develUpgrade proftpd-ldapUpgrade proftpd-pgsqlUpgrade proftpd-lang | Mar 3, 2020 | Feb 20, 2020 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Feb 20, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub