Use-after-free in ProFTPD - CVE-2020-9273
Published: February 25, 2020 / Updated: September 7, 2020
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error when processing data transfer within the alloc_pool() function in pool.c. A remote authenticated attacker can trigger a use-after-free error and execute arbitrary code on the system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
Affected software
QNAP QTS
Gentoo Linux
Fedora
SUSE Linux
Opensuse
SIMATIC NET CP 1545-1
SIMATIC NET CP 1543-1
proftpd-dfsg (Debian package)
proftpd
How to mitigate CVE-2020-9273
proftpd-dfsg (Debian package) - addressed in versions 1.3.5b-4+deb9u4, 1.3.6-4+deb10u4
QNAP QTS - addressed in versions 4.2.6 20200821, 4.3.3.1386 20200821, 4.3.6.1411 20200825, 4.4.3.1400 20200817
proftpd - addressed in versions 1.3.3g-14.el6, 1.3.5e-9.el7, 1.3.6c-1.el8, 1.3.6c-1.fc30, 1.3.6c-1.fc31
SIMATIC NET CP 1543-1 - update to 3.0
External References
Related Security Bulletins
- Multiple vulnerabilities in ProFTPD
- Debian update for proftpd-dfsg
- OpenSUSE Linux update for proftpd
- Gentoo update for ProFTPd
- Security update for third-party software in QNAP QTS
- Multiple vulnerabilities in Siemens SIMATIC NET CP
- Fedora 30 update for proftpd
- Fedora 31 update for proftpd
- Fedora EPEL 8 update for proftpd
- Fedora EPEL 7 update for proftpd
- Fedora EPEL 6 update for proftpd