Bugzilla – Bug 1164574
VUL-0: CVE-2020-9273: proftpd: possibility of corrupting memory pool by interrupting the data transfer channel
Last modified: 2020-05-04 08:43:09 UTC
CVE-2020-9273 In ProFTPD 1.3.7, it is possible to corrupt the memory pool by interrupting the data transfer channel. This triggers a use-after-free in alloc_pool in pool.c, and possible remote code execution. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-9273 http://people.canonical.com/~ubuntu-security/cve/2020/CVE-2020-9273.html
ongoing work ...
This is an autogenerated message for OBS integration: This bug (1164574) was mentioned in https://build.opensuse.org/request/show/778858 Factory / proftpd
This is an autogenerated message for OBS integration: This bug (1164574) was mentioned in https://build.opensuse.org/request/show/778895 15.1+Backports:SLE-15+Backports:SLE-15-SP1 / proftpd
openSUSE-SU-2020:0273-1: An update that fixes two vulnerabilities is now available. Category: security (moderate) Bug References: 1164572,1164574 CVE References: CVE-2020-9272,CVE-2020-9273 Sources used: openSUSE Leap 15.1 (src): proftpd-1.3.6c-lp151.3.9.1 openSUSE Backports SLE-15-SP1 (src): proftpd-1.3.6c-bp151.4.9.1 openSUSE Backports SLE-15 (src): proftpd-1.3.6c-bp150.3.9.1
can we close this ?
Done