Vulnerabilities
Vulnerable Software
Proftpd:  >> Proftpd  >> 1.3.5b  Security Vulnerabilities
An issue was discovered in tls_verify_crl in ProFTPD before 1.3.6. A wrong iteration variable, used when checking a client certificate against CRL entries (installed by a system administrator), can cause some CRL entries to be ignored, and can allow clients whose certificates have been revoked to proceed with a connection to the server.
CVSS Score
7.5
EPSS Score
0.011
Published
2019-11-26
An issue was discovered in tls_verify_crl in ProFTPD before 1.3.6. Direct dereference of a NULL pointer (a variable initialized to NULL) leads to a crash when validating the certificate of a client connecting to the server in a TLS client/server mutual-authentication setup.
CVSS Score
7.5
EPSS Score
0.009
Published
2019-11-26
An arbitrary file copy vulnerability in mod_copy in ProFTPD up to 1.3.5b allows for remote code execution and information disclosure without authentication, a related issue to CVE-2015-3306.
CVSS Score
9.8
EPSS Score
0.576
Published
2019-07-19


Contact Us

Shodan ® - All rights reserved