ProFTPD 1.3.7 has an out-of-bounds (OOB) read vulnerability in mod_cap via the cap_text.c cap_to_text function.
References
Link | Resource |
---|---|
http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00002.html | Mailing List Third Party Advisory |
https://cert-portal.siemens.com/productcert/pdf/ssa-679335.pdf | Third Party Advisory |
https://github.com/proftpd/proftpd/blob/master/RELEASE_NOTES | Release Notes Third Party Advisory |
https://github.com/proftpd/proftpd/issues/902 | Issue Tracking Patch Third Party Advisory |
https://security.gentoo.org/glsa/202003-35 | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
|
History
09 Nov 2021, 17:48
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:o:siemens:simatic_net_cp_1545-1_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:* cpe:2.3:a:opensuse:backports_sle:15.0:sp1:*:*:*:*:*:* cpe:2.3:o:siemens:simatic_net_cp_1543-1_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:siemens:simatic_net_cp_1543-1:-:*:*:*:*:*:*:* cpe:2.3:h:siemens:simatic_net_cp_1545-1:-:*:*:*:*:*:*:* cpe:2.3:a:proftpd:proftpd:*:*:*:*:*:*:*:* cpe:2.3:a:opensuse:backports_sle:15.0:-:*:*:*:*:*:* |
|
References |
|
|
References | (CONFIRM) https://github.com/proftpd/proftpd/issues/902 - Issue Tracking, Patch, Third Party Advisory | |
References | (GENTOO) https://security.gentoo.org/glsa/202003-35 - Third Party Advisory | |
References | (SUSE) http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00002.html - Mailing List, Third Party Advisory |
Information
Published : 2020-02-20 16:15
Updated : 2024-02-04 20:39
NVD link : CVE-2020-9272
Mitre link : CVE-2020-9272
CVE.ORG link : CVE-2020-9272
JSON object : View
Products Affected
opensuse
- backports_sle
- leap
siemens
- simatic_net_cp_1543-1_firmware
- simatic_net_cp_1545-1_firmware
- simatic_net_cp_1543-1
- simatic_net_cp_1545-1
proftpd
- proftpd
CWE
CWE-125
Out-of-bounds Read