make_ftp_cmd in main.c in ProFTPD before 1.3.8a has a one-byte out-of-bounds read, and daemon crash, because of mishandling of quote/backslash semantics.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade proftpd-dfsg | Jul 30, 2024 | Dec 22, 2023 |
| Huawei Euleros 2_0_sp10 | — | Upgrade proftpd | Mar 13, 2024 | Dec 22, 2023 |
| Huawei Euleros 2_0_sp11 | — | Upgrade proftpd | Mar 13, 2024 | Dec 22, 2023 |
| Huawei Euleros 2_0_sp12 | — | Upgrade proftpd | May 31, 2024 | Dec 22, 2023 |
| Proftp Proftpd | — | Update ProFTP ProFTPd to the latest version | Nov 6, 2025 | Dec 22, 2023 |
| Suse | — | Upgrade proftpd-ldapUpgrade proftpd-sqliteUpgrade proftpd-langUpgrade proftpd-radiusUpgrade proftpd-docUpgrade proftpd-develUpgrade proftpd-mysqlUpgrade proftpdUpgrade proftpd-pgsql | Jan 4, 2024 | Dec 22, 2023 |
| Ubuntu | — | Upgrade proftpd-coreUpgrade proftpd-basic | Feb 26, 2025 | Dec 22, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub