PT-2019-15799 · Proftpd+2 · Proftpd+2
Debrouxl
·
Publicado
2019-07-30
·
Atualizado
2025-10-22
·
CVE-2019-19271
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:N/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
ProFTPD versions prior to 1.3.6
Description
An issue was discovered in the tls verify crl function, where a wrong iteration variable is used when checking a client certificate against Certificate Revocation List (CRL) entries. This can cause some CRL entries to be ignored, allowing clients with revoked certificates to connect to the server.
Recommendations
For versions prior to 1.3.6, update to version 1.3.6 or later to resolve the issue.
Correção
Improper Certificate Validation
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Proftpd
Red Os