CVE-2019-19271: High severity proftpd vulnerability
An issue was discovered in tlsverifycrl in ProFTPD before 1.3.6. A wrong iteration variable, used when checking a client certificate against CRL entries (installed by a system administrator), can cause some CRL entries to be ignored, and can allow clients whose certificates have been revoked to proceed with a connection to the server.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-19271?
CVE-2019-19271 is a vulnerability in ProFTPD, an open-source FTP server, that allows clients with revoked certificates to connect to the server.
What is the severity of CVE-2019-19271?
CVE-2019-19271 has a severity rating of 7.5, which is considered high.
How does CVE-2019-19271 affect ProFTPD?
CVE-2019-19271 affects ProFTPD versions up to and excluding 1.3.6.
How can clients exploit CVE-2019-19271?
Clients with revoked certificates can exploit CVE-2019-19271 to establish a connection to the ProFTPD server.
Is there a fix for CVE-2019-19271?
Yes, upgrading ProFTPD to version 1.3.6 or later fixes the vulnerability CVE-2019-19271.