Memory leak in ProFTPD - CVE-2021-46854

 

Memory leak in ProFTPD - CVE-2021-46854

Published: May 3, 2023


Vulnerability identifier: #VU75703
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-46854
CWE-ID: CWE-401
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due memory leak in mod_radius. A remote attacker can force the application to disclose memory to the RADIUS server.


Affected software

ProFTPD
Gentoo Linux
openEuler
LANTIME Operating System Firmware (LTOS)
proftpd
proftpd-debuginfo
proftpd-utils
proftpd-postgresql
proftpd-ldap
proftpd-sqlite
proftpd-devel
proftpd-mysql
proftpd-debugsource
net-ftp/proftpd

How to mitigate CVE-2021-46854

Install updates from vendor's website.

ProFTPD - update to 1.3.7c
LANTIME Operating System Firmware (LTOS) - update to 7.08.007
proftpd - update to 1.3.7a-2
proftpd-debuginfo - update to 1.3.7a-2
proftpd-utils - update to 1.3.7a-2
proftpd-postgresql - update to 1.3.7a-2
proftpd-ldap - update to 1.3.7a-2
proftpd-sqlite - update to 1.3.7a-2
proftpd-devel - update to 1.3.7a-2
proftpd-mysql - update to 1.3.7a-2
proftpd-debugsource - update to 1.3.7a-2
net-ftp/proftpd - update to 1.3.7c

External References

Related Security Bulletins