CVE-2019-19269 PUBLISHED

An issue was discovered in tls_verify_crl in ProFTPD through 1.3.6b. A dereference of a NULL pointer may occur. This pointer is returned by the OpenSSL sk_X509_REVOKED_value() function when encountering an empty CRL installed by a system administrator. The dereference occurs when validating the certificate of a client connecting to the server in a TLS client/server mutual-authentication setup.

EPSS 1.69% · 82.1th percentile

Risk Scores

EPSS Score
1.69%
82.1th percentile

Affected Products

VendorProductVersions
Ubuntu:20.04:LTSproftpd-dfsg1.3.6c-2ubuntu0.1, 1.3.6c-2, 1.3.6c-1
Ubuntu:24.04:LTSproftpd-dfsg1.3.8.a+dfsg-1, 1.3.8.b+dfsg-1build1, 1.3.8.b+dfsg-1build2
Ubuntu:18.04:LTSproftpd-dfsg1.3.5e-1build1, 1.3.5d-1, 0
Ubuntu:25.10proftpd-dfsg1.3.9~dfsg-3, 0, 1.3.8.c+dfsg-4
Ubuntu:16.04:LTSproftpd-dfsg0, 1.3.5-2, 1.3.5a-1
Ubuntu:22.04:LTSproftpd-dfsg1.3.7c+dfsg-1ubuntu0.1, 1.3.7c+dfsg-1build1, 1.3.7b+dfsg-1

Timeline

References

Open in Interactive Console →