Improper access control in ProFTPD - CVE-2015-3306

 

Improper access control in ProFTPD - CVE-2015-3306

Published: September 23, 2018 / Updated: April 19, 2024


Vulnerability identifier: #VU14904
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-3306
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to read and write files to the system.

The vulnerability exists due to improper access restrictions when handling CPFR and SITE CPTO FTP commends. A remote unauthenticated attacker can read and write arbitrary files on the system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


Affected software

ProFTPD
Debian Linux
Fedora
Slackware Linux
proftpd

How to mitigate CVE-2015-3306

Install updates from vendor's website.

proftpd - addressed in versions 1.3.5-5.el7, 1.3.5-5.fc21, 1.3.5-6.fc22

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins