CVE-2019-18217: High severity proftpd vulnerability
ProFTPD before 1.3.6b and 1.3.7rc before 1.3.7rc2 allows remote unauthenticated denial-of-service due to incorrect handling of overly long commands because main.c in a child process enters an infinite loop.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-18217?
CVE-2019-18217 is a vulnerability in ProFTPD versions before 1.3.6b and 1.3.7rc before 1.3.7rc2 that allows remote unauthenticated denial-of-service attacks.
How severe is CVE-2019-18217?
CVE-2019-18217 has a severity rating of 7.5 (high).
What is the affected software of CVE-2019-18217?
The affected software of CVE-2019-18217 includes ProFTPD versions 1.3.5, 1.3.6, 1.3.6-a, 1.3.6-rc1, 1.3.6-rc2, 1.3.6-rc3, 1.3.6-rc4, and 1.3.7-rc1.
How can I fix CVE-2019-18217?
To fix CVE-2019-18217, it is recommended to update ProFTPD to version 1.3.6b or 1.3.7rc2, or apply the appropriate security patches provided by the vendor.
Where can I find more information about CVE-2019-18217?
You can find more information about CVE-2019-18217 on the following references: http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00009.html, https://cert-portal.siemens.com/productcert/pdf/ssa-940889.pdf, and https://github.com/proftpd/proftpd/blob/1.3.6/NEWS