CWE
NVD-CWE-Other
Advisory Published
Updated

CVE-2005-2390

First published: Wed Jul 27 2005(Updated: )

Multiple format string vulnerabilities in ProFTPD before 1.3.0rc2 allow attackers to cause a denial of service or obtain sensitive information via (1) certain inputs to the shutdown message from ftpshut, or (2) the SQLShowInfo mod_sql directive.

Credit: cve@mitre.org

Affected SoftwareAffected VersionHow to fix
ProFTPD=1.2.10_rc2
ProFTPD=1.2.3
ProFTPD=1.2.6_rc2
ProFTPD=1.2.6_rc3
ProFTPD=1.2.1
ProFTPD=1.2.7_rc3
ProFTPD=1.2.4
ProFTPD=1.2.7_rc2
ProFTPD=1.2.5_rc2
ProFTPD=1.3.0_rc1
ProFTPD=1.2.9
ProFTPD=1.2.0_rc1
ProFTPD=1.2.10_rc1
ProFTPD=1.2.1_final
ProFTPD=1.2.0_pre9
ProFTPD=1.2.9_rc2
ProFTPD=1.2.0_rc2
ProFTPD=1.2.7
ProFTPD=1.2.2_rc1
ProFTPD=1.2.6
ProFTPD=1.2.10_rc3
ProFTPD=1.2.8_rc1
ProFTPD=1.2.6_rc1
ProFTPD=1.2.9_rc1
ProFTPD=1.2.2_rc2
ProFTPD=1.2.0_rc3
ProFTPD=1.2.7_rc1
ProFTPD=1.2.8
ProFTPD=1.2.2_rc3
ProFTPD=1.2.9_rc3
ProFTPD=1.2.5_rc3
ProFTPD=1.2.8_rc2
ProFTPD=1.2.5
ProFTPD=1.2.2
ProFTPD=1.2.0_pre10
ProFTPD=1.2.10
ProFTPD=1.2.5_rc1

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of CVE-2005-2390?

    CVE-2005-2390 has a moderate severity level as it can cause denial of service and potentially expose sensitive information.

  • How do I fix CVE-2005-2390?

    To fix CVE-2005-2390, upgrade ProFTPD to version 1.3.0rc2 or later.

  • Which ProFTPD versions are affected by CVE-2005-2390?

    ProFTPD versions before 1.3.0rc2, including 1.2.1 through 1.2.10 and several release candidates, are affected by CVE-2005-2390.

  • What types of vulnerabilities are associated with CVE-2005-2390?

    CVE-2005-2390 includes multiple format string vulnerabilities that can lead to denial of service and information disclosure.

  • Is CVE-2005-2390 a critical vulnerability?

    CVE-2005-2390 is not classified as critical, but it should still be addressed to prevent potential exploits.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203