VDB
CVE-2020-9273
CVE-2020-9273
PUBLISHED
In ProFTPD 1.3.7, it is possible to corrupt the memory pool by interrupting the data transfer channel. This triggers a use-after-free in alloc_pool in pool.c, and possible remote code execution.
EPSS 60.22% · 98.3th percentile
Risk Scores
EPSS Score
60.22%
98.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:16.04:LTS | proftpd-dfsg | 1.3.5a-1ubuntu0.1, 1.3.5-2, 1.3.5a-1 |
| Ubuntu:18.04:LTS | proftpd-dfsg | 1.3.5e-1build1, *, 0 |
Exploit Intelligence
- Analysis and exploitation of an use-after-free in ProFTPd (github-poc-repo)
- Analysis and exploitation of an use-after-free in ProFTPd (github-poc-repo)
- Analysis and exploitation of an use-after-free in ProFTPd (github-poc-repo)
- Analysis and exploitation of an use-after-free in ProFTPd (github-poc-repo)
- Analysis and exploitation of an use-after-free in ProFTPd (github-poc-repo)
- Analysis and exploitation of an use-after-free in ProFTPd (github-poc-repo)
- Analysis and exploitation of an use-after-free in ProFTPd (github-poc-repo)
- Analysis and exploitation of an use-after-free in ProFTPd (github-poc)
- Analysis and exploitation of an use-after-free in ProFTPd (github-poc)
- Analysis and exploitation of an use-after-free in ProFTPd (github-poc)
…and 15 more exploits
Timeline
- Feb 20, 2020 CVE Published
- Apr 14, 2021 EPSS Score
- Aug 11, 2021 EPSS Score
- Aug 26, 2021 EPSS Score
- Sep 7, 2021 EPSS Score
- Apr 1, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
- Mar 9, 2023 EPSS Score
- May 24, 2023 EPSS Score
- Nov 8, 2023 EPSS Score
- Aug 4, 2024 CVE Updated
- Dec 17, 2024 EPSS Score
References
- https://ubuntu.com/security/CVE-2020-9273 third-party-advisory
- https://github.com/proftpd/proftpd/issues/903 third-party-advisory
- https://github.com/proftpd/proftpd/commit/d388f7904d4c9a6d0ea54237b8b54a57c19d8d49 third-party-advisory
- https://github.com/proftpd/proftpd/commit/e845abc1bd86eebec7a0342fded908a1b0f1996b third-party-advisory
- https://github.com/proftpd/proftpd/blob/master/RELEASE_NOTES third-party-advisory
- https://www.cve.org/CVERecord?id=CVE-2020-9273 third-party-advisory