PT-2019-15798 · Proftpd+3 · Proftpd+3
Debrouxl
·
Published
2019-11-25
·
Updated
2025-10-22
·
CVE-2019-19270
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
ProFTPD versions prior to 1.3.7
Description
An issue was discovered in the tls verify crl function, which prevents some valid Certificate Revocation Lists (CRLs) from being taken into account. This can allow clients whose certificates have been revoked to connect to the server.
Recommendations
For ProFTPD versions prior to 1.3.7, update to version 1.3.7 or later to resolve the issue.
Exploit
Fix
DoS
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Proftpd
Red Os
Suse