Potential NULL Pointer Dereference in ProFTPD Affects Multiple Systems
CVE-2019-19269

4.9MEDIUM

Key Information:

Vendor

Proftpd

Status
Vendor
CVE Published:
30 November 2019

What is CVE-2019-19269?

A vulnerability in the ProFTPD server may lead to a NULL pointer dereference due to a flaw in the tls_verify_crl function. This issue arises when an empty Certificate Revocation List (CRL) is installed by an administrator, causing the sk_X509_REVOKED_value() function from OpenSSL to return a NULL pointer. When a client connects via TLS mutual-authentication, the server attempts to validate the client's certificate, leading to potential disruption in service.

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.