NULL pointer dereference in ProFTPD - CVE-2024-57392

 

NULL pointer dereference in ProFTPD - CVE-2024-57392

Published: February 18, 2025


Vulnerability identifier: #VU104049
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-57392
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to perform a denial of service (DoS) attack.

The vulnerability exists due to a NULL pointer dereference error. A remote authenticated user can pass specially crafted data to the application and perform a denial of service (DoS) attack.


Affected software

ProFTPD
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
Fedora
Server Applications Module
openSUSE Leap
openEuler
LANTIME Operating System Firmware (LTOS)
proftpd-utils
proftpd
proftpd-debuginfo
proftpd-debugsource
proftpd-devel
proftpd-ldap
proftpd-mysql
proftpd-postgresql
proftpd-sqlite
proftpd-radius-debuginfo
proftpd-doc
proftpd-sqlite-debuginfo
proftpd-pgsql-debuginfo
proftpd-pgsql
proftpd-ldap-debuginfo
proftpd-mysql-debuginfo
proftpd-radius
proftpd-lang

How to mitigate CVE-2024-57392

Install updates from vendor's website.

LANTIME Operating System Firmware (LTOS) - update to 7.08.021
proftpd-utils - addressed in versions 1.3.8b-4, 1.3.8b-6, 1.3.8b-7
proftpd - addressed in versions 1.3.8b-4, 1.3.8b-6, 1.3.8b-7
proftpd-debuginfo - addressed in versions 1.3.8b-4, 1.3.8b-6, 1.3.8b-7
proftpd-debugsource - addressed in versions 1.3.8b-4, 1.3.8b-6, 1.3.8b-7
proftpd-devel - addressed in versions 1.3.8b-4, 1.3.8b-6, 1.3.8b-7
proftpd-ldap - addressed in versions 1.3.8b-4, 1.3.8b-6, 1.3.8b-7
proftpd-mysql - addressed in versions 1.3.8b-4, 1.3.8b-6, 1.3.8b-7
proftpd-postgresql - addressed in versions 1.3.8b-4, 1.3.8b-6, 1.3.8b-7
proftpd-sqlite - addressed in versions 1.3.8b-4, 1.3.8b-6, 1.3.8b-7
proftpd-sqlite - update to 1.3.8b-150600.13.6.1
proftpd-devel - update to 1.3.8b-150600.13.6.1
proftpd-radius-debuginfo - update to 1.3.8b-150600.13.6.1
proftpd-doc - update to 1.3.8b-150600.13.6.1
proftpd-sqlite-debuginfo - update to 1.3.8b-150600.13.6.1
proftpd - update to 1.3.8b-150600.13.6.1
proftpd-pgsql-debuginfo - update to 1.3.8b-150600.13.6.1
proftpd-pgsql - update to 1.3.8b-150600.13.6.1
proftpd-debugsource - update to 1.3.8b-150600.13.6.1
proftpd-ldap-debuginfo - update to 1.3.8b-150600.13.6.1
proftpd-mysql - update to 1.3.8b-150600.13.6.1
proftpd-mysql-debuginfo - update to 1.3.8b-150600.13.6.1
proftpd-ldap - update to 1.3.8b-150600.13.6.1
proftpd-radius - update to 1.3.8b-150600.13.6.1
proftpd-debuginfo - update to 1.3.8b-150600.13.6.1
proftpd-lang - update to 1.3.8b-150600.13.6.1
proftpd - addressed in versions 1.3.8c-2.el9, 1.3.8c-3.fc40, 1.3.8c-3.fc41

External References

Related Security Bulletins