CVE Vulnerabilities

CVE-2011-1137

Published: Mar 11, 2011 | Modified: Sep 07, 2011
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

Integer overflow in the mod_sftp (aka SFTP) module in ProFTPD 1.3.3d and earlier allows remote attackers to cause a denial of service (memory consumption leading to OOM kill) via a malformed SSH message.

Affected Software

Name Vendor Start Version End Version
Proftpd Proftpd * 1.3.3 (including)
Proftpd Proftpd 1.2.0 (including) 1.2.0 (including)
Proftpd Proftpd 1.2.0-pre10 (including) 1.2.0-pre10 (including)
Proftpd Proftpd 1.2.0-pre9 (including) 1.2.0-pre9 (including)
Proftpd Proftpd 1.2.0-rc1 (including) 1.2.0-rc1 (including)
Proftpd Proftpd 1.2.0-rc2 (including) 1.2.0-rc2 (including)
Proftpd Proftpd 1.2.0-rc3 (including) 1.2.0-rc3 (including)
Proftpd Proftpd 1.2.1 (including) 1.2.1 (including)
Proftpd Proftpd 1.2.2 (including) 1.2.2 (including)
Proftpd Proftpd 1.2.2-rc1 (including) 1.2.2-rc1 (including)
Proftpd Proftpd 1.2.2-rc2 (including) 1.2.2-rc2 (including)
Proftpd Proftpd 1.2.2-rc3 (including) 1.2.2-rc3 (including)
Proftpd Proftpd 1.2.3 (including) 1.2.3 (including)
Proftpd Proftpd 1.2.4 (including) 1.2.4 (including)
Proftpd Proftpd 1.2.5 (including) 1.2.5 (including)
Proftpd Proftpd 1.2.5-rc1 (including) 1.2.5-rc1 (including)
Proftpd Proftpd 1.2.5-rc2 (including) 1.2.5-rc2 (including)
Proftpd Proftpd 1.2.5-rc3 (including) 1.2.5-rc3 (including)
Proftpd Proftpd 1.2.6 (including) 1.2.6 (including)
Proftpd Proftpd 1.2.6-rc1 (including) 1.2.6-rc1 (including)
Proftpd Proftpd 1.2.6-rc2 (including) 1.2.6-rc2 (including)
Proftpd Proftpd 1.2.7 (including) 1.2.7 (including)
Proftpd Proftpd 1.2.7-rc1 (including) 1.2.7-rc1 (including)
Proftpd Proftpd 1.2.7-rc2 (including) 1.2.7-rc2 (including)
Proftpd Proftpd 1.2.7-rc3 (including) 1.2.7-rc3 (including)
Proftpd Proftpd 1.2.8 (including) 1.2.8 (including)
Proftpd Proftpd 1.2.8-rc1 (including) 1.2.8-rc1 (including)
Proftpd Proftpd 1.2.8-rc2 (including) 1.2.8-rc2 (including)
Proftpd Proftpd 1.2.9 (including) 1.2.9 (including)
Proftpd Proftpd 1.2.9-rc1 (including) 1.2.9-rc1 (including)
Proftpd Proftpd 1.2.9-rc2 (including) 1.2.9-rc2 (including)
Proftpd Proftpd 1.2.9-rc3 (including) 1.2.9-rc3 (including)
Proftpd Proftpd 1.2.10 (including) 1.2.10 (including)
Proftpd Proftpd 1.2.10-rc1 (including) 1.2.10-rc1 (including)
Proftpd Proftpd 1.2.10-rc2 (including) 1.2.10-rc2 (including)
Proftpd Proftpd 1.2.10-rc3 (including) 1.2.10-rc3 (including)
Proftpd Proftpd 1.3.0 (including) 1.3.0 (including)
Proftpd Proftpd 1.3.0-a (including) 1.3.0-a (including)
Proftpd Proftpd 1.3.0-rc1 (including) 1.3.0-rc1 (including)
Proftpd Proftpd 1.3.0-rc2 (including) 1.3.0-rc2 (including)
Proftpd Proftpd 1.3.0-rc3 (including) 1.3.0-rc3 (including)
Proftpd Proftpd 1.3.0-rc4 (including) 1.3.0-rc4 (including)
Proftpd Proftpd 1.3.0-rc5 (including) 1.3.0-rc5 (including)
Proftpd Proftpd 1.3.1 (including) 1.3.1 (including)
Proftpd Proftpd 1.3.1-rc1 (including) 1.3.1-rc1 (including)
Proftpd Proftpd 1.3.1-rc2 (including) 1.3.1-rc2 (including)
Proftpd Proftpd 1.3.1-rc3 (including) 1.3.1-rc3 (including)
Proftpd Proftpd 1.3.2 (including) 1.3.2 (including)
Proftpd Proftpd 1.3.2-a (including) 1.3.2-a (including)
Proftpd Proftpd 1.3.2-b (including) 1.3.2-b (including)
Proftpd Proftpd 1.3.2-c (including) 1.3.2-c (including)
Proftpd Proftpd 1.3.2-d (including) 1.3.2-d (including)
Proftpd Proftpd 1.3.2-e (including) 1.3.2-e (including)
Proftpd Proftpd 1.3.2-rc1 (including) 1.3.2-rc1 (including)
Proftpd Proftpd 1.3.2-rc2 (including) 1.3.2-rc2 (including)
Proftpd Proftpd 1.3.2-rc3 (including) 1.3.2-rc3 (including)
Proftpd Proftpd 1.3.2-rc4 (including) 1.3.2-rc4 (including)
Proftpd Proftpd 1.3.3 (including) 1.3.3 (including)
Proftpd Proftpd 1.3.3-a (including) 1.3.3-a (including)
Proftpd Proftpd 1.3.3-b (including) 1.3.3-b (including)
Proftpd Proftpd 1.3.3-c (including) 1.3.3-c (including)
Proftpd Proftpd 1.3.3-rc1 (including) 1.3.3-rc1 (including)
Proftpd Proftpd 1.3.3-rc2 (including) 1.3.3-rc2 (including)
Proftpd Proftpd 1.3.3-rc3 (including) 1.3.3-rc3 (including)
Proftpd Proftpd 1.3.3-rc4 (including) 1.3.3-rc4 (including)
Proftpd-dfsg Ubuntu hardy *
Proftpd-dfsg Ubuntu karmic *

References