CVE-2020-9273: Use After Free
In ProFTPD 1.3.7, it is possible to corrupt the memory pool by interrupting the data transfer channel. This triggers a use-after-free in allocpool in pool.c, and possible remote code execution.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/proftpd-dfsgto a version that resolves this vulnerability.Fixed in 1.3.6-4+deb10u6Fixed in 1.3.6-4+deb10u4Fixed in 1.3.7a+dfsg-12+deb11u2Fixed in 1.3.8+dfsg-4+deb12u1Fixed in 1.3.8+dfsg-8 - Upgrade
Upgrade
debian/proftpd-dfsgto a version that resolves this vulnerability.Fixed in 1.3.6c-1Fixed in 1.3.5b-4+deb9u4Fixed in 1.3.6-4+deb10u4
Event History
Frequently Asked Questions
What is the vulnerability ID for this ProFTPD vulnerability?
The vulnerability ID is CVE-2020-9273.
What is the severity of CVE-2020-9273?
CVE-2020-9273 has a severity rating of critical (8.8).
What software versions are affected by CVE-2020-9273?
ProFTPD versions 1.3.7 and prior are affected.
How can CVE-2020-9273 be exploited?
CVE-2020-9273 can be exploited by interrupting the data transfer channel in ProFTPD 1.3.7, which triggers a use-after-free vulnerability and may lead to remote code execution.
Is there a fix available for CVE-2020-9273?
Yes, the fix for CVE-2020-9273 is included in ProFTPD versions 1.3.7a, 1.3.8, and later.