PT-2019-2795 · Proftpd+2 · Proftpd+2

Tobias Maedel

·

Published

2018-01-02

·

Updated

2025-11-04

·

CVE-2019-12815

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions ProFTPD versions up to 1.3.5b
Description The issue is related to an arbitrary file copy vulnerability in the mod copy module of ProFTPD, allowing for remote code execution and information disclosure without authentication. This can be exploited by sending CPFR and CPTO commands to the ProFTPD server, potentially enabling an attacker to execute arbitrary code on the target system. The vulnerability is severe and affects over 1 million servers.
Recommendations For ProFTPD versions up to 1.3.5b, update to a version that contains a fix for this issue to prevent remote code execution and information disclosure. As a temporary workaround, consider disabling the mod copy module until a patch is available. Restrict access to the FTP server to minimize the risk of exploitation, especially when anonymous access is provided.

Exploit

Fix

RCE

Improper Handling of Exceptional Conditions

Improper Access Control

Weakness Enumeration

Related Identifiers

ALT-PU-2018-1000
ALT-PU-2019-2329
ALT-PU-2019-2647
ALT-PU-2020-2973
ALT-PU-2020-2992
ALT-PU-2021-2692
ALT-PU-2023-5874
ALT-PU-2024-13729
BDU:2019-02747
CVE-2019-12815
DLA-1873-1
DSA-4491-1
MGASA-2019-0314
OPENSUSE-SU-2019:1836-1
OPENSUSE-SU-2019:1870-1
OPENSUSE-SU-2019_1836-1
OPENSUSE-SU-2020:0031-1
OPENSUSE-SU-2020_0031-1
OPENSUSE-SU-2024:11196-1

Affected Products

Alt Linux
Proftpd
Suse