Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Marti2203

#32150of 53,634
7.8Total CVSS
Vulnerabilities · 1
PT-2023-8972
7.8
2023-12-21
Proftpd · Proftpd · CVE-2023-51713
**Name of the Vulnerable Software and Affected Versions** ProFTPD versions prior to 1.3.8a **Description** The issue is related to the `make ftp cmd` function in the `main.c` component of the ProFTPD FTP server, which mishandles quote and backslash semantics. This leads to a one-byte out-of-bounds read and can cause the daemon to crash. The vulnerability can be exploited by a remote attacker to cause a denial of service. **Recommendations** For ProFTPD versions prior to 1.3.8a, update to version 1.3.8a or later to resolve the issue. As a temporary workaround, consider restricting access to the FTP server until the update can be applied.