Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-19269


An issue was discovered in tls_verify_crl in ProFTPD through 1.3.6b. A dereference of a NULL pointer may occur. This pointer is returned by the OpenSSL sk_X509_REVOKED_value() function when encountering an empty CRL installed by a system administrator. The dereference occurs when validating the certificate of a client connecting to the server in a TLS client/server mutual-authentication setup.


Published

2019-11-30T23:15:18.223

Last Modified

2024-11-21T04:34:27.800

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 4.9 (MEDIUM)

CVSSv2 Vector

AV:N/AC:L/Au:S/C:N/I:N/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: SINGLE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: PARTIAL
Exploitability Score

8.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-476

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application proftpd proftpd ≤ 1.3.5e Yes
Application proftpd proftpd 1.3.6 Yes
Application proftpd proftpd 1.3.6 Yes
Application proftpd proftpd 1.3.6 Yes
Application proftpd proftpd 1.3.6 Yes
Application proftpd proftpd 1.3.6 Yes
Application proftpd proftpd 1.3.6 Yes
Application proftpd proftpd 1.3.6 Yes
Operating System fedoraproject fedora 30 Yes
Operating System fedoraproject fedora 31 Yes
Operating System debian debian_linux 8.0 Yes

References