CVE-2021-46854: High severity proftpd vulnerability
Published Nov 23, 2022
·Updated
modradius in ProFTPD before 1.3.7c allows memory disclosure to RADIUS servers because it copies blocks of 16 characters.
Affected Software
1 affected component
ProFTPD ProFTPD<1.3.7c
Event History
Nov 23, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-46854.
2
What is the title of this vulnerability?
The title of this vulnerability is "mod_radius in ProFTPD before 1.3.7c allows memory disclosure to RADIUS servers because it copies blocks of 16 characters."
3
How does this vulnerability affect ProFTPD?
This vulnerability affects ProFTPD versions up to and excluding 1.3.7c.
4
What is the severity of CVE-2021-46854?
The severity of CVE-2021-46854 is high, with a severity value of 7.5.
5
How can this vulnerability be fixed?
To fix this vulnerability, upgrade to ProFTPD version 1.3.7c or later.