CVE-2015-3306: Critical severity proftpd vulnerability
Published May 18, 2015
·Updated
The modcopy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.
Affected Software
1 affected component
ProFTPD ProFTPD=1.3.5
Event History
May 18, 2015
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-3306?
CVE-2015-3306 is classified as a high severity vulnerability due to its potential for unauthorized file access.
2
How do I fix CVE-2015-3306?
To fix CVE-2015-3306, upgrade ProFTPD to a version later than 1.3.5 that addresses this vulnerability.
3
What types of attacks are possible with CVE-2015-3306?
CVE-2015-3306 allows attackers to read and write arbitrary files on the server, which can lead to data breaches.
4
Which versions of ProFTPD are affected by CVE-2015-3306?
CVE-2015-3306 affects ProFTPD version 1.3.5.
5
How can I verify if CVE-2015-3306 is present in my installation?
You can verify CVE-2015-3306 by checking your installed version of ProFTPD and assessing the configuration for the mod_copy module.