Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-51713


make_ftp_cmd in main.c in ProFTPD before 1.3.8a has a one-byte out-of-bounds read, and daemon crash, because of mishandling of quote/backslash semantics.


Published

2023-12-22T03:15:09.730

Last Modified

2024-11-21T08:38:39.543

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

Weaknesses
  • Type: Primary
    CWE-125

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application proftpd proftpd < 1.3.8a Yes

References