#VU30581 NULL pointer dereference in ProFTPD - CVE-2019-19272
Published: November 26, 2019 / Updated: September 7, 2020
ProFTPD
ProFTPD
Description
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
An issue was discovered in tls_verify_crl in ProFTPD before 1.3.6. Direct dereference of a NULL pointer (a variable initialized to NULL) leads to a crash when validating the certificate of a client connecting to the server in a TLS client/server mutual-authentication setup.