Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Mageia: 2020-0120 Critical Update For ProFTPD Denial Of Service

mageia
Calendar Grey March 6, 2020
Dist Mageia Esm H88
Mageia 2020-0120 resolves a significant security issue in ProFTPD that poses a threat of denial of service resulting from memory mismanagement. Learn more.
Updated proftpd packages fix security vulnerability: Antonio Morales discovered an use-after-free flaw in the memory pool allocator in ProFTPD

Summary

Updated proftpd packages fix security vulnerability:
Antonio Morales discovered an use-after-free flaw in the memory pool allocator in ProFTPD. Interrupting current data transfers can corrupt the ProFTPD memory pool, leading to denial of service, or potentially the execution of arbitrary code (CVE-2020-9273).

References

- https://bugs.mageia.org/show_bug.cgi?id=26251

- https://lists.debian.org/debian-security-announce/2020/msg00038.html

- https://www.cve.org/CVERecord?id=CVE-2020-9273

Resolution

SRPMS

- 7/core/proftpd-1.3.5e-4.3.mga7

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 06 Mar 2020
URL: https://advisories.mageia.org/MGASA-2020-0120.html
Type: security
CVE: CVE-2020-9273

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here