Memory leak in ProFTPD - CVE-2021-46854
Published: May 3, 2023
Vulnerability identifier: #VU75703
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-46854
CWE-ID: CWE-401
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due memory leak in mod_radius. A remote attacker can force the application to disclose memory to the RADIUS server.
Affected software
ProFTPD
Gentoo Linux
openEuler
LANTIME Operating System Firmware (LTOS)
proftpd
proftpd-debuginfo
proftpd-utils
proftpd-postgresql
proftpd-ldap
proftpd-sqlite
proftpd-devel
proftpd-mysql
proftpd-debugsource
net-ftp/proftpd
Gentoo Linux
openEuler
LANTIME Operating System Firmware (LTOS)
proftpd
proftpd-debuginfo
proftpd-utils
proftpd-postgresql
proftpd-ldap
proftpd-sqlite
proftpd-devel
proftpd-mysql
proftpd-debugsource
net-ftp/proftpd
How to mitigate CVE-2021-46854
Install updates from vendor's website.
ProFTPD - update to 1.3.7c
LANTIME Operating System Firmware (LTOS) - update to 7.08.007
proftpd - update to 1.3.7a-2
proftpd-debuginfo - update to 1.3.7a-2
proftpd-utils - update to 1.3.7a-2
proftpd-postgresql - update to 1.3.7a-2
proftpd-ldap - update to 1.3.7a-2
proftpd-sqlite - update to 1.3.7a-2
proftpd-devel - update to 1.3.7a-2
proftpd-mysql - update to 1.3.7a-2
proftpd-debugsource - update to 1.3.7a-2
net-ftp/proftpd - update to 1.3.7c
LANTIME Operating System Firmware (LTOS) - update to 7.08.007
proftpd - update to 1.3.7a-2
proftpd-debuginfo - update to 1.3.7a-2
proftpd-utils - update to 1.3.7a-2
proftpd-postgresql - update to 1.3.7a-2
proftpd-ldap - update to 1.3.7a-2
proftpd-sqlite - update to 1.3.7a-2
proftpd-devel - update to 1.3.7a-2
proftpd-mysql - update to 1.3.7a-2
proftpd-debugsource - update to 1.3.7a-2
net-ftp/proftpd - update to 1.3.7c