Use-after-free in ProFTPD - CVE-2020-9273

 

Use-after-free in ProFTPD - CVE-2020-9273

Published: February 25, 2020 / Updated: September 7, 2020


Vulnerability identifier: #VU25595
CSH Severity: Medium
CVSS v4: 7.7 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-9273
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error when processing data transfer within the alloc_pool() function in pool.c. A remote authenticated attacker can trigger a use-after-free error and execute arbitrary code on the system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


Affected software

ProFTPD
QNAP QTS
Gentoo Linux
Fedora
SUSE Linux
Opensuse
SIMATIC NET CP 1545-1
SIMATIC NET CP 1543-1
proftpd-dfsg (Debian package)
proftpd

How to mitigate CVE-2020-9273

Install updates from vendor's website.

ProFTPD - addressed in versions 1.3.6c, 1.3.7 rc3
proftpd-dfsg (Debian package) - addressed in versions 1.3.5b-4+deb9u4, 1.3.6-4+deb10u4
QNAP QTS - addressed in versions 4.2.6 20200821, 4.3.3.1386 20200821, 4.3.6.1411 20200825, 4.4.3.1400 20200817
proftpd - addressed in versions 1.3.3g-14.el6, 1.3.5e-9.el7, 1.3.6c-1.el8, 1.3.6c-1.fc30, 1.3.6c-1.fc31
SIMATIC NET CP 1543-1 - update to 3.0

External References

Related Security Bulletins