Wind River Support Network

HomeDefectsLIN8-12175
Fixed

LIN8-12175 : Security Advisory - proftpd - CVE-2020-9273

Created: Feb 20, 2020    Updated: Apr 22, 2022
Resolved Date: Apr 20, 2020
Found In Version: 8.0.0.1
Fix Version: 8.0.0.33
Severity: Standard
Applicable for: Wind River Linux 8
Component/s: Userspace

Description

In ProFTPD 1.3.7, it is possible to corrupt the memory pool by interrupting the data transfer channel. This triggers a use-after-free in alloc_pool in pool.c, and possible remote code execution.

CREATE(Triage):(User=admin) CVE-2020-9273 (https://nvd.nist.gov/vuln/detail/CVE-2020-9273)

CVEs


Live chat
Online