Upstream information
CVE-2019-18217 at MITRE
Description
ProFTPD before 1.3.6b and 1.3.7rc before 1.3.7rc2 allows remote unauthenticated denial-of-service due to incorrect handling of overly long commands because main.c in a child process enters an infinite loop.
Overall state of this security issue: Resolved
This issue is currently rated as having moderate severity.
CVSS v2 Scores
| | National Vulnerability Database |
| Base Score | 5 |
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
| Access Vector | Network |
| Access Complexity | Low |
| Authentication | None |
| Confidentiality Impact | None |
| Integrity Impact | None |
| Availability Impact | Partial |
SUSE Bugzilla entry:
1154600 [RESOLVED / FIXED]
SUSE Security Advisories:
List of released packages
| Product(s) | Fixed package version(s) | References |
| SUSE Package Hub 15 SP1 | proftpd >= 1.3.6b-bp151.4.6.2
proftpd-devel >= 1.3.6b-bp151.4.6.2
proftpd-doc >= 1.3.6b-bp151.4.6.2
proftpd-lang >= 1.3.6b-bp151.4.6.2
proftpd-ldap >= 1.3.6b-bp151.4.6.2
proftpd-mysql >= 1.3.6b-bp151.4.6.2
proftpd-pgsql >= 1.3.6b-bp151.4.6.2
proftpd-radius >= 1.3.6b-bp151.4.6.2
proftpd-sqlite >= 1.3.6b-bp151.4.6.2
| Patchnames: openSUSE-2020-31 |
| SUSE Package Hub 15 | proftpd >= 1.3.6b-bp150.3.6.1
proftpd-devel >= 1.3.6b-bp150.3.6.1
proftpd-doc >= 1.3.6b-bp150.3.6.1
proftpd-lang >= 1.3.6b-bp150.3.6.1
proftpd-ldap >= 1.3.6b-bp150.3.6.1
proftpd-mysql >= 1.3.6b-bp150.3.6.1
proftpd-pgsql >= 1.3.6b-bp150.3.6.1
proftpd-radius >= 1.3.6b-bp150.3.6.1
proftpd-sqlite >= 1.3.6b-bp150.3.6.1
| Patchnames: openSUSE-2020-31 |
| openSUSE Leap 15.1 | proftpd >= 1.3.6b-lp151.3.6.1
proftpd-devel >= 1.3.6b-lp151.3.6.1
proftpd-doc >= 1.3.6b-lp151.3.6.1
proftpd-lang >= 1.3.6b-lp151.3.6.1
proftpd-ldap >= 1.3.6b-lp151.3.6.1
proftpd-mysql >= 1.3.6b-lp151.3.6.1
proftpd-pgsql >= 1.3.6b-lp151.3.6.1
proftpd-radius >= 1.3.6b-lp151.3.6.1
proftpd-sqlite >= 1.3.6b-lp151.3.6.1
| Patchnames: openSUSE-2020-31 |
| openSUSE Tumbleweed | proftpd >= 1.3.6e-1.10
proftpd-devel >= 1.3.6e-1.10
proftpd-doc >= 1.3.6e-1.10
proftpd-lang >= 1.3.6e-1.10
proftpd-ldap >= 1.3.6e-1.10
proftpd-mysql >= 1.3.6e-1.10
proftpd-pgsql >= 1.3.6e-1.10
proftpd-radius >= 1.3.6e-1.10
proftpd-sqlite >= 1.3.6e-1.10
| Patchnames: openSUSE-Tumbleweed-2024-11196 |
SUSE Timeline for this CVE
CVE page created: Mon Oct 21 10:08:53 2019
CVE page last modified: Tue Sep 3 19:14:30 2024