Upstream information
CVE-2019-18217 at MITRE
Description
ProFTPD before 1.3.6b and 1.3.7rc before 1.3.7rc2 allows remote unauthenticated denial-of-service due to incorrect handling of overly long commands because main.c in a child process enters an infinite loop.
Overall state of this security issue: Resolved
This issue is currently rated as having moderate severity.
CVSS v2 Scores
| National Vulnerability Database |
Base Score | 5 |
Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Access Vector | Network |
Access Complexity | Low |
Authentication | None |
Confidentiality Impact | None |
Integrity Impact | None |
Availability Impact | Partial |
SUSE Bugzilla entry:
1154600 [RESOLVED / FIXED]
SUSE Security Advisories:
List of released packages
Product(s) | Fixed package version(s) | References |
SUSE Package Hub 15 SP1 | proftpd >= 1.3.6b-bp151.4.6.2
proftpd-devel >= 1.3.6b-bp151.4.6.2
proftpd-doc >= 1.3.6b-bp151.4.6.2
proftpd-lang >= 1.3.6b-bp151.4.6.2
proftpd-ldap >= 1.3.6b-bp151.4.6.2
proftpd-mysql >= 1.3.6b-bp151.4.6.2
proftpd-pgsql >= 1.3.6b-bp151.4.6.2
proftpd-radius >= 1.3.6b-bp151.4.6.2
proftpd-sqlite >= 1.3.6b-bp151.4.6.2
| Patchnames: openSUSE-2020-31 |
SUSE Package Hub 15 | proftpd >= 1.3.6b-bp150.3.6.1
proftpd-devel >= 1.3.6b-bp150.3.6.1
proftpd-doc >= 1.3.6b-bp150.3.6.1
proftpd-lang >= 1.3.6b-bp150.3.6.1
proftpd-ldap >= 1.3.6b-bp150.3.6.1
proftpd-mysql >= 1.3.6b-bp150.3.6.1
proftpd-pgsql >= 1.3.6b-bp150.3.6.1
proftpd-radius >= 1.3.6b-bp150.3.6.1
proftpd-sqlite >= 1.3.6b-bp150.3.6.1
| Patchnames: openSUSE-2020-31 |
openSUSE Leap 15.1 | proftpd >= 1.3.6b-lp151.3.6.1
proftpd-devel >= 1.3.6b-lp151.3.6.1
proftpd-doc >= 1.3.6b-lp151.3.6.1
proftpd-lang >= 1.3.6b-lp151.3.6.1
proftpd-ldap >= 1.3.6b-lp151.3.6.1
proftpd-mysql >= 1.3.6b-lp151.3.6.1
proftpd-pgsql >= 1.3.6b-lp151.3.6.1
proftpd-radius >= 1.3.6b-lp151.3.6.1
proftpd-sqlite >= 1.3.6b-lp151.3.6.1
| Patchnames: openSUSE-2020-31 |
openSUSE Tumbleweed | proftpd >= 1.3.6e-1.10
proftpd-devel >= 1.3.6e-1.10
proftpd-doc >= 1.3.6e-1.10
proftpd-lang >= 1.3.6e-1.10
proftpd-ldap >= 1.3.6e-1.10
proftpd-mysql >= 1.3.6e-1.10
proftpd-pgsql >= 1.3.6e-1.10
proftpd-radius >= 1.3.6e-1.10
proftpd-sqlite >= 1.3.6e-1.10
| Patchnames: openSUSE-Tumbleweed-2024-11196 |
SUSE Timeline for this CVE
CVE page created: Mon Oct 21 10:08:53 2019
CVE page last modified: Tue Sep 3 19:14:30 2024