An arbitrary file copy vulnerability in mod_copy in ProFTPD up to 1.3.5b allows for remote code execution and information disclosure without authentication, a related issue to CVE-2015-3306.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade proftpd-dfsg | Aug 6, 2019 | Jul 19, 2019 |
| Ftp Proftpd | — | No fixes or workaround suggested by the vendor | Jul 31, 2019 | Jul 19, 2019 |
| Gentoo Linux | — | Upgrade net-ftp/proftpd. | Aug 16, 2019 | Jul 19, 2019 |
| Proftp Proftpd | — | Update ProFTP ProFTPd to the latest version | Nov 6, 2025 | Jul 19, 2019 |
| Suse | — | Upgrade proftpd-langUpgrade proftpd-ldapUpgrade proftpdUpgrade proftpd-docUpgrade proftpd-develUpgrade proftpd-pgsqlUpgrade proftpd-radiusUpgrade proftpd-mysqlUpgrade proftpd-sqlite | Aug 9, 2019 | Jul 19, 2019 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Jul 19, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub