Bugzilla – Bug 1218344
VUL-0: CVE-2023-51713: proftpd: make_ftp_cmd in main.c has a one-byte out-of-bounds read, and daemon crash
Last modified: 2024-01-04 09:42:38 UTC
make_ftp_cmd in main.c in ProFTPD before 1.3.8a has a one-byte out-of-bounds read, and daemon crash, because of mishandling of quote/backslash semantics. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-51713 https://github.com/proftpd/proftpd/issues/1683 Patch: https://github.com/proftpd/proftpd/commit/97bbe68363ccf2de0c07f67170ec64a8b4d62592
fixed with Update to 1.3.8a
This is an autogenerated message for OBS integration: This bug (1218344) was mentioned in https://build.opensuse.org/request/show/1136558 Backports:SLE-15-SP5 / proftpd
I guess this can be closed
openSUSE-SU-2024:0008-1: An update that fixes two vulnerabilities is now available. Category: security (important) Bug References: 1218144,1218344 CVE References: CVE-2023-48795,CVE-2023-51713 JIRA References: Sources used: openSUSE Backports SLE-15-SP5 (src): proftpd-1.3.8b-bp155.2.6.1
Fixed