Proftpd · Proftpd · CVE-2019-19271
**Name of the Vulnerable Software and Affected Versions**
ProFTPD versions prior to 1.3.6
**Description**
An issue was discovered in the tls verify crl function, where a wrong iteration variable is used when checking a client certificate against Certificate Revocation List (CRL) entries. This can cause some CRL entries to be ignored, allowing clients with revoked certificates to connect to the server.
**Recommendations**
For versions prior to 1.3.6, update to version 1.3.6 or later to resolve the issue.