Out-of-Bounds Read Vulnerability in ProFTPD Product by ProFTPD
CVE-2023-51713

7.5HIGH

Key Information:

Vendor

Proftpd

Status
Vendor
CVE Published:
22 December 2023

What is CVE-2023-51713?

The make_ftp_cmd function in the main.c file of ProFTPD versions prior to 1.3.8a is susceptible to a one-byte out-of-bounds read. This vulnerability can lead to a daemon crash due to improper handling of quote and backslash semantics. This flaw underscores the necessity for stringent input validation and error handling to maintain the integrity and availability of the FTP server.

References

EPSS Score

72% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.