NULL pointer dereference in ProFTPD - CVE-2019-19272
Published: November 26, 2019 / Updated: September 7, 2020
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
An issue was discovered in tls_verify_crl in ProFTPD before 1.3.6. Direct dereference of a NULL pointer (a variable initialized to NULL) leads to a crash when validating the certificate of a client connecting to the server in a TLS client/server mutual-authentication setup.
Affected software
QNAP QTS
Fedora
proftpd
How to mitigate CVE-2019-19272
QNAP QTS - addressed in versions 4.2.6 20200821, 4.3.3.1386 20200821, 4.3.6.1411 20200825, 4.4.3.1400 20200817
proftpd - update to 1.3.5e-8.el7