CVE-2005-2390: Medium severity Proftpd Project Proftpd vulnerability

Published Jul 27, 2005
·
Updated

Multiple format string vulnerabilities in ProFTPD before 1.3.0rc2 allow attackers to cause a denial of service or obtain sensitive information via (1) certain inputs to the shutdown message from ftpshut, or (2) the SQLShowInfo modsql directive.

Affected Software

37 affected components
Proftpd Project Proftpd=1.2.10_rc2
Proftpd Project Proftpd=1.2.3
Proftpd Project Proftpd=1.2.6_rc2
Proftpd Project Proftpd=1.2.6_rc3
Proftpd Project Proftpd=1.2.1
Proftpd Project Proftpd=1.2.7_rc3
Proftpd Project Proftpd=1.2.4
Proftpd Project Proftpd=1.2.7_rc2
Proftpd Project Proftpd=1.2.5_rc2
Proftpd Project Proftpd=1.3.0_rc1
Proftpd Project Proftpd=1.2.9
Proftpd Project Proftpd=1.2.0_rc1
Proftpd Project Proftpd=1.2.10_rc1
Proftpd Project Proftpd=1.2.1_final
Proftpd Project Proftpd=1.2.0_pre9
Proftpd Project Proftpd=1.2.9_rc2
Proftpd Project Proftpd=1.2.0_rc2
Proftpd Project Proftpd=1.2.7
Proftpd Project Proftpd=1.2.2_rc1
Proftpd Project Proftpd=1.2.6
Proftpd Project Proftpd=1.2.10_rc3
Proftpd Project Proftpd=1.2.8_rc1
Proftpd Project Proftpd=1.2.6_rc1
Proftpd Project Proftpd=1.2.9_rc1
Proftpd Project Proftpd=1.2.2_rc2
Proftpd Project Proftpd=1.2.0_rc3
Proftpd Project Proftpd=1.2.7_rc1
Proftpd Project Proftpd=1.2.8
Proftpd Project Proftpd=1.2.2_rc3
Proftpd Project Proftpd=1.2.9_rc3
Proftpd Project Proftpd=1.2.5_rc3
Proftpd Project Proftpd=1.2.8_rc2
Proftpd Project Proftpd=1.2.5
Proftpd Project Proftpd=1.2.2
Proftpd Project Proftpd=1.2.0_pre10
Proftpd Project Proftpd=1.2.10
Proftpd Project Proftpd=1.2.5_rc1

Event History

Jul 27, 2005
CVE Published
04:00 AM
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2005-2390?

CVE-2005-2390 has a moderate severity level as it can cause denial of service and potentially expose sensitive information.

2

How do I fix CVE-2005-2390?

To fix CVE-2005-2390, upgrade ProFTPD to version 1.3.0rc2 or later.

3

Which ProFTPD versions are affected by CVE-2005-2390?

ProFTPD versions before 1.3.0rc2, including 1.2.1 through 1.2.10 and several release candidates, are affected by CVE-2005-2390.

4

What types of vulnerabilities are associated with CVE-2005-2390?

CVE-2005-2390 includes multiple format string vulnerabilities that can lead to denial of service and information disclosure.

5

Is CVE-2005-2390 a critical vulnerability?

CVE-2005-2390 is not classified as critical, but it should still be addressed to prevent potential exploits.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203