CVE-2020-9272: High severity ProFTPD ProFTPD vulnerability
Published Feb 20, 2020
·Updated
ProFTPD 1.3.7 has an out-of-bounds (OOB) read vulnerability in modcap via the captext.c captotext function.
Affected Software
12 affected components
ProFTPD ProFTPD<1.3.6c
Siemens Simatic Net Cp 1543-1 Firmware<3.0
Siemens Simatic Net Cp 1543-1
Siemens Simatic Net Cp 1545-1 Firmware
Siemens Simatic Net Cp 1545-1
openSUSE Backports SLE=15.0
openSUSE Backports SLE=15.0-sp1
openSUSE Leap=15.1
All of the following
Siemens Simatic Net Cp 1543-1 Firmware<3.0
Siemens Simatic Net Cp 1543-1
All of the following
Siemens Simatic Net Cp 1545-1 Firmware
Siemens Simatic Net Cp 1545-1
Remediation
Patch Available
Event History
Feb 20, 2020
CVE Published
via MITRE·03:17 PM
Data Sourced
via MITRE·03:17 PM
Description
Data Sourced
via NVD·04:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2020-9272?
CVE-2020-9272 is a vulnerability in ProFTPD 1.3.7 that allows for an out-of-bounds (OOB) read via the cap_text.c cap_to_text function.
2
Which software versions are affected by CVE-2020-9272?
ProFTPD 1.3.7 is affected by CVE-2020-9272.
3
What is the severity of CVE-2020-9272?
CVE-2020-9272 has a severity rating of high (7.5).
4
How can I mitigate the vulnerability in CVE-2020-9272?
To mitigate the vulnerability in CVE-2020-9272, it is recommended to update to a version higher than 1.3.7.
5
Where can I find more information about CVE-2020-9272?
More information about CVE-2020-9272 can be found in the following references: [1] http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00002.html [2] https://cert-portal.siemens.com/productcert/pdf/ssa-679335.pdf [3] https://github.com/proftpd/proftpd/blob/master/RELEASE_NOTES