Back to Database
Status published
Medium
CVE-2011-1137
Integer overflow in the mod_sftp (aka SFTP) module in ProFTPD...
Vulnerability Description
Integer overflow in the mod_sftp (aka SFTP) module in ProFTPD 1.3.3d and earlier allows remote attackers to cause a denial of service (memory consumption leading to OOM kill) via a malformed SSH message.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2011-1137
Credits & Attribution
No credits recorded in the NVD database.
References
- http://slackware.com/security/viewer.php?l=slackware-security&y=2011&m=slackware-security.485806
- http://proftp.cvs.sourceforge.net/viewvc/proftp/proftpd/contrib/mod_sftp/packet.h?r1=1.3&r2=1.3.2.1
- http://www.exploit-db.com/exploits/16129/
- http://secunia.com/advisories/43978
- http://www.vupen.com/english/advisories/2011/0857
- https://bugzilla.redhat.com/show_bug.cgi?id=681718
- http://www.securityfocus.com/bid/46183
- http://www.debian.org/security/2011/dsa-2185
- http://bugs.proftpd.org/show_bug.cgi?id=3586
- http://bugs.proftpd.org/show_bug.cgi?id=3587
- http://proftp.cvs.sourceforge.net/viewvc/proftp/proftpd/contrib/mod_sftp/packet.c?r1=1.14.2.2&r2=1.14.2.3
- http://www.vupen.com/english/advisories/2011/0617
- http://proftp.cvs.sourceforge.net/viewvc/proftp/proftpd/contrib/mod_sftp/mod_sftp.c?r1=1.29.2.1&r2=1.29.2.2
- http://lists.fedoraproject.org/pipermail/package-announce/2011-April/058344.html
- http://secunia.com/advisories/43234
- http://lists.fedoraproject.org/pipermail/package-announce/2011-April/058356.html
- http://secunia.com/advisories/43635
More from proftpd
View All →CVE-2021-46854
mod_radius in ProFTPD before 1.3.7c allows memory disclosure to RADIUS...
Unknown
0
CVE-2020-9273
In ProFTPD 1.3.7, it is possible to corrupt the memory...
High
8.8
CVE-2020-9272
ProFTPD 1.3.7 has an out-of-bounds (OOB) read vulnerability in mod_cap...
High
7.5
CVE-2019-19272
An issue was discovered in tls_verify_crl in ProFTPD before 1.3.6....
High
7.5
CVE-2019-19271
An issue was discovered in tls_verify_crl in ProFTPD before 1.3.6....
High
7.5
Affected Vendor
proftpd
View all reports →Affected Software
proftpd
Vulnerable Versions:
0, 1.2.0, 1.2.1, 1.2.2, 1.2.3, 1.2.4, 1.2.5, 1.2.6, 1.2.7, 1.2.8, 1.2.9, 1.2.10, 1.3.0, 1.3.1, 1.3.2, 1.3.3
Timeline
Official Publish:
March 11th, 2011
Last Modified:
August 6th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.