Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.113645
Categoría:FTP
Título:ProFTPD < 1.3.7 Multiple Vulnerabilities
Resumen:ProFTPD is prone to multiple vulnerabilities.
Descripción:Summary:
ProFTPD is prone to multiple vulnerabilities.

Vulnerability Insight:
The following vulnerabilities exist:

- There is an out-of-bounds (OOB) read vulnerability in mod_cap
via the cap_text.c cap_to_text function.

- It is possible to corrupt the memory pool by interrupting the data transfer channel.
This triggers a use-after-free in alloc_pool in pool.c.

Vulnerability Impact:
Successful exploitation would allow an attacker to read sensitive information
or execute arbitrary code on the target machine.

Affected Software/OS:
ProFTPD through version 1.3.6.

Solution:
Update to version 1.3.7.

CVSS Score:
9.0

CVSS Vector:
AV:N/AC:L/Au:S/C:C/I:C/A:C

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2020-9272
https://security.gentoo.org/glsa/202003-35
SuSE Security Announcement: openSUSE-SU-2020:0273 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00002.html
Common Vulnerability Exposure (CVE) ID: CVE-2020-9273
Debian Security Information: DSA-4635 (Google Search)
https://www.debian.org/security/2020/dsa-4635
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XHO3S5WPRRP7VGKIAHLYQVEYW5HRYIJN/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VCUPRYSJR7XOM3HQ6H5M4OGDU7OHCHBF/
https://lists.debian.org/debian-lts-announce/2020/02/msg00022.html
https://lists.debian.org/debian-lts-announce/2020/03/msg00002.html
http://www.openwall.com/lists/oss-security/2021/08/25/1
http://www.openwall.com/lists/oss-security/2021/09/06/2
CopyrightCopyright (C) 2020 Greenbone Networks GmbH

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.