PT-2019-2795 · Proftpd+2 · Proftpd+2
Tobias Maedel
·
Published
2018-01-02
·
Updated
2025-11-04
·
CVE-2019-12815
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
ProFTPD versions up to 1.3.5b
Description
The issue is related to an arbitrary file copy vulnerability in the mod copy module of ProFTPD, allowing for remote code execution and information disclosure without authentication. This can be exploited by sending CPFR and CPTO commands to the ProFTPD server, potentially enabling an attacker to execute arbitrary code on the target system. The vulnerability is severe and affects over 1 million servers.
Recommendations
For ProFTPD versions up to 1.3.5b, update to a version that contains a fix for this issue to prevent remote code execution and information disclosure.
As a temporary workaround, consider disabling the mod copy module until a patch is available.
Restrict access to the FTP server to minimize the risk of exploitation, especially when anonymous access is provided.
Exploit
Fix
RCE
Improper Handling of Exceptional Conditions
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Proftpd
Suse