PT-2020-5165 · Proftpd+3 · Proftpd+3

Antonio Morales

·

Published

2018-01-02

·

Updated

2025-10-22

·

CVE-2020-9273

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions ProFTPD version 1.3.7
Description The issue is related to a use-after-free vulnerability in the alloc pool function of the ProFTPD FTP server. This vulnerability can be triggered by interrupting the data transfer channel, which can lead to memory corruption and possible remote code execution. The vulnerability is associated with the use of memory after it has been freed.
Recommendations For ProFTPD version 1.3.7, consider updating to a newer version that contains a fix for this issue, as no specific workaround or patch is mentioned in the provided information. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

DoS

Use After Free

Weakness Enumeration

Related Identifiers

ALT-PU-2018-1000
ALT-PU-2020-2973
ALT-PU-2020-2975
ALT-PU-2020-2992
ALT-PU-2021-2692
ALT-PU-2023-5707
ALT-PU-2023-5874
ALT-PU-2024-13729
BDU:2020-05776
CVE-2020-9273
DLA-2115-1
DLA-2115-2
DSA-4635-1
MGASA-2020-0120
OPENSUSE-SU-2020:0273-1
OPENSUSE-SU-2020_0273-1
OPENSUSE-SU-2024:11196-1

Affected Products

Alt Linux
Proftpd
Red Os
Suse