make_ftp_cmd in main.c in ProFTPD before 1.3.8a has a one...
High severity
Unreviewed
Published
Dec 22, 2023
to the GitHub Advisory Database
•
Updated Jan 17, 2024
Description
Published by the National Vulnerability Database
Dec 22, 2023
Published to the GitHub Advisory Database
Dec 22, 2023
Last updated
Jan 17, 2024
make_ftp_cmd in main.c in ProFTPD before 1.3.8a has a one-byte out-of-bounds read, and daemon crash, because of mishandling of quote/backslash semantics.
References