CVE-2020-9273
20.02.2020, 16:15
In ProFTPD 1.3.7, it is possible to corrupt the memory pool by interrupting the data transfer channel. This triggers a use-after-free in alloc_pool in pool.c, and possible remote code execution.Enginsight
Vendor | Product | Version |
---|---|---|
proftpd | proftpd | 1.3.7 |
debian | debian_linux | 8.0 |
debian | debian_linux | 9.0 |
debian | debian_linux | 10.0 |
opensuse | backports_sle | 15.0 |
opensuse | backports_sle | 15.0:sp1 |
opensuse | leap | 15.1 |
siemens | simatic_net_cp_1545-1_firmware | - |
siemens | simatic_net_cp_1543-1_firmware | 𝑥 < 3.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References