CVE-2010-4652
02.02.2011, 01:00
Heap-based buffer overflow in the sql_prepare_where function (contrib/mod_sql.c) in ProFTPD before 1.3.3d, when mod_sql is enabled, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted username containing substitution tags, which are not properly handled during construction of an SQL query.Enginsight
Vendor | Product | Version |
---|---|---|
proftpd | proftpd | 𝑥 ≤ 1.3.3 |
proftpd | proftpd | 1.2.0 |
proftpd | proftpd | 1.2.0:pre10 |
proftpd | proftpd | 1.2.0:pre9 |
proftpd | proftpd | 1.2.0:rc1 |
proftpd | proftpd | 1.2.0:rc2 |
proftpd | proftpd | 1.2.0:rc3 |
proftpd | proftpd | 1.2.1 |
proftpd | proftpd | 1.2.2 |
proftpd | proftpd | 1.2.2:rc1 |
proftpd | proftpd | 1.2.2:rc2 |
proftpd | proftpd | 1.2.2:rc3 |
proftpd | proftpd | 1.2.3 |
proftpd | proftpd | 1.2.4 |
proftpd | proftpd | 1.2.5 |
proftpd | proftpd | 1.2.5:rc1 |
proftpd | proftpd | 1.2.5:rc2 |
proftpd | proftpd | 1.2.5:rc3 |
proftpd | proftpd | 1.2.6 |
proftpd | proftpd | 1.2.6:rc1 |
proftpd | proftpd | 1.2.6:rc2 |
proftpd | proftpd | 1.2.7 |
proftpd | proftpd | 1.2.7:rc1 |
proftpd | proftpd | 1.2.7:rc2 |
proftpd | proftpd | 1.2.7:rc3 |
proftpd | proftpd | 1.2.8 |
proftpd | proftpd | 1.2.8:rc1 |
proftpd | proftpd | 1.2.8:rc2 |
proftpd | proftpd | 1.2.9 |
proftpd | proftpd | 1.2.9:rc1 |
proftpd | proftpd | 1.2.9:rc2 |
proftpd | proftpd | 1.2.9:rc3 |
proftpd | proftpd | 1.2.10 |
proftpd | proftpd | 1.2.10:rc1 |
proftpd | proftpd | 1.2.10:rc2 |
proftpd | proftpd | 1.2.10:rc3 |
proftpd | proftpd | 1.3.0 |
proftpd | proftpd | 1.3.0:a |
proftpd | proftpd | 1.3.0:rc1 |
proftpd | proftpd | 1.3.0:rc2 |
proftpd | proftpd | 1.3.0:rc3 |
proftpd | proftpd | 1.3.0:rc4 |
proftpd | proftpd | 1.3.0:rc5 |
proftpd | proftpd | 1.3.1 |
proftpd | proftpd | 1.3.1:rc1 |
proftpd | proftpd | 1.3.1:rc2 |
proftpd | proftpd | 1.3.1:rc3 |
proftpd | proftpd | 1.3.2 |
proftpd | proftpd | 1.3.2:a |
proftpd | proftpd | 1.3.2:b |
proftpd | proftpd | 1.3.2:c |
proftpd | proftpd | 1.3.2:d |
proftpd | proftpd | 1.3.2:e |
proftpd | proftpd | 1.3.2:rc1 |
proftpd | proftpd | 1.3.2:rc2 |
proftpd | proftpd | 1.3.2:rc3 |
proftpd | proftpd | 1.3.2:rc4 |
proftpd | proftpd | 1.3.3 |
proftpd | proftpd | 1.3.3:a |
proftpd | proftpd | 1.3.3:b |
proftpd | proftpd | 1.3.3:rc1 |
proftpd | proftpd | 1.3.3:rc2 |
proftpd | proftpd | 1.3.3:rc3 |
proftpd | proftpd | 1.3.3:rc4 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References