Back to Database
Status published
High
CVE-2020-9273
In ProFTPD 1.3.7, it is possible to corrupt the memory...
Vulnerability Description
In ProFTPD 1.3.7, it is possible to corrupt the memory pool by interrupting the data transfer channel. This triggers a use-after-free in alloc_pool in pool.c, and possible remote code execution.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-9273
Credits & Attribution
No credits recorded in the NVD database.
References
- https://github.com/proftpd/proftpd/blob/master/RELEASE_NOTES
- https://github.com/proftpd/proftpd/issues/903
- https://lists.debian.org/debian-lts-announce/2020/02/msg00022.html
- https://www.debian.org/security/2020/dsa-4635
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XHO3S5WPRRP7VGKIAHLYQVEYW5HRYIJN/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VCUPRYSJR7XOM3HQ6H5M4OGDU7OHCHBF/
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00002.html
- https://lists.debian.org/debian-lts-announce/2020/03/msg00002.html
- https://security.gentoo.org/glsa/202003-35
- https://cert-portal.siemens.com/productcert/pdf/ssa-679335.pdf
- http://www.openwall.com/lists/oss-security/2021/08/25/1
- http://www.openwall.com/lists/oss-security/2021/09/06/2
More from proftpd
View All →CVE-2021-46854
mod_radius in ProFTPD before 1.3.7c allows memory disclosure to RADIUS...
Unknown
0
CVE-2020-9272
ProFTPD 1.3.7 has an out-of-bounds (OOB) read vulnerability in mod_cap...
High
7.5
CVE-2019-19272
An issue was discovered in tls_verify_crl in ProFTPD before 1.3.6....
High
7.5
CVE-2019-19271
An issue was discovered in tls_verify_crl in ProFTPD before 1.3.6....
High
7.5
CVE-2019-19270
An issue was discovered in tls_verify_crl in ProFTPD through 1.3.6b....
High
7.5
Affected Vendor
proftpd
View all reports →Affected Software
proftpd, debian linux, fedora, backports sle, leap, simatic net cp 1545-1 firmware, simatic net cp 1543-1 firmware
Vulnerable Versions:
1.3.7, 8.0, 9.0, 10.0, 30, 31, 15.0, 15.1, 0
Timeline
Official Publish:
February 20th, 2020
Last Modified:
August 4th, 2024
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.