CVE Vulnerabilities

CVE-2011-4130

Published: Dec 06, 2011 | Modified: Dec 08, 2011
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9 HIGH
AV:N/AC:L/Au:S/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

Use-after-free vulnerability in the Response API in ProFTPD before 1.3.3g allows remote authenticated users to execute arbitrary code via vectors involving an error that occurs after an FTP data transfer.

Affected Software

Name Vendor Start Version End Version
Proftpd Proftpd * 1.3.3 (including)
Proftpd Proftpd 1.2.0 (including) 1.2.0 (including)
Proftpd Proftpd 1.2.0-pre10 (including) 1.2.0-pre10 (including)
Proftpd Proftpd 1.2.0-pre9 (including) 1.2.0-pre9 (including)
Proftpd Proftpd 1.2.0-rc1 (including) 1.2.0-rc1 (including)
Proftpd Proftpd 1.2.0-rc2 (including) 1.2.0-rc2 (including)
Proftpd Proftpd 1.2.0-rc3 (including) 1.2.0-rc3 (including)
Proftpd Proftpd 1.2.1 (including) 1.2.1 (including)
Proftpd Proftpd 1.2.2 (including) 1.2.2 (including)
Proftpd Proftpd 1.2.2-rc1 (including) 1.2.2-rc1 (including)
Proftpd Proftpd 1.2.2-rc2 (including) 1.2.2-rc2 (including)
Proftpd Proftpd 1.2.2-rc3 (including) 1.2.2-rc3 (including)
Proftpd Proftpd 1.2.3 (including) 1.2.3 (including)
Proftpd Proftpd 1.2.4 (including) 1.2.4 (including)
Proftpd Proftpd 1.2.5 (including) 1.2.5 (including)
Proftpd Proftpd 1.2.5-rc1 (including) 1.2.5-rc1 (including)
Proftpd Proftpd 1.2.5-rc2 (including) 1.2.5-rc2 (including)
Proftpd Proftpd 1.2.5-rc3 (including) 1.2.5-rc3 (including)
Proftpd Proftpd 1.2.6 (including) 1.2.6 (including)
Proftpd Proftpd 1.2.6-rc1 (including) 1.2.6-rc1 (including)
Proftpd Proftpd 1.2.6-rc2 (including) 1.2.6-rc2 (including)
Proftpd Proftpd 1.2.7 (including) 1.2.7 (including)
Proftpd Proftpd 1.2.7-rc1 (including) 1.2.7-rc1 (including)
Proftpd Proftpd 1.2.7-rc2 (including) 1.2.7-rc2 (including)
Proftpd Proftpd 1.2.7-rc3 (including) 1.2.7-rc3 (including)
Proftpd Proftpd 1.2.8 (including) 1.2.8 (including)
Proftpd Proftpd 1.2.8-rc1 (including) 1.2.8-rc1 (including)
Proftpd Proftpd 1.2.8-rc2 (including) 1.2.8-rc2 (including)
Proftpd Proftpd 1.2.9 (including) 1.2.9 (including)
Proftpd Proftpd 1.2.9-rc1 (including) 1.2.9-rc1 (including)
Proftpd Proftpd 1.2.9-rc2 (including) 1.2.9-rc2 (including)
Proftpd Proftpd 1.2.9-rc3 (including) 1.2.9-rc3 (including)
Proftpd Proftpd 1.2.10 (including) 1.2.10 (including)
Proftpd Proftpd 1.2.10-rc1 (including) 1.2.10-rc1 (including)
Proftpd Proftpd 1.2.10-rc2 (including) 1.2.10-rc2 (including)
Proftpd Proftpd 1.2.10-rc3 (including) 1.2.10-rc3 (including)
Proftpd Proftpd 1.3.0 (including) 1.3.0 (including)
Proftpd Proftpd 1.3.0-a (including) 1.3.0-a (including)
Proftpd Proftpd 1.3.0-rc1 (including) 1.3.0-rc1 (including)
Proftpd Proftpd 1.3.0-rc2 (including) 1.3.0-rc2 (including)
Proftpd Proftpd 1.3.0-rc3 (including) 1.3.0-rc3 (including)
Proftpd Proftpd 1.3.0-rc4 (including) 1.3.0-rc4 (including)
Proftpd Proftpd 1.3.0-rc5 (including) 1.3.0-rc5 (including)
Proftpd Proftpd 1.3.1 (including) 1.3.1 (including)
Proftpd Proftpd 1.3.1-rc1 (including) 1.3.1-rc1 (including)
Proftpd Proftpd 1.3.1-rc2 (including) 1.3.1-rc2 (including)
Proftpd Proftpd 1.3.1-rc3 (including) 1.3.1-rc3 (including)
Proftpd Proftpd 1.3.2 (including) 1.3.2 (including)
Proftpd Proftpd 1.3.2-rc1 (including) 1.3.2-rc1 (including)
Proftpd Proftpd 1.3.2-rc2 (including) 1.3.2-rc2 (including)
Proftpd Proftpd 1.3.2-rc3 (including) 1.3.2-rc3 (including)
Proftpd Proftpd 1.3.2-rc4 (including) 1.3.2-rc4 (including)
Proftpd Proftpd 1.3.3 (including) 1.3.3 (including)
Proftpd Proftpd 1.3.3-a (including) 1.3.3-a (including)
Proftpd Proftpd 1.3.3-b (including) 1.3.3-b (including)
Proftpd Proftpd 1.3.3-c (including) 1.3.3-c (including)
Proftpd Proftpd 1.3.3-d (including) 1.3.3-d (including)
Proftpd Proftpd 1.3.3-e (including) 1.3.3-e (including)
Proftpd Proftpd 1.3.3-rc1 (including) 1.3.3-rc1 (including)
Proftpd Proftpd 1.3.3-rc2 (including) 1.3.3-rc2 (including)
Proftpd Proftpd 1.3.3-rc3 (including) 1.3.3-rc3 (including)
Proftpd Proftpd 1.3.3-rc4 (including) 1.3.3-rc4 (including)
Proftpd-dfsg Ubuntu lucid *
Proftpd-dfsg Ubuntu maverick *
Proftpd-dfsg Ubuntu natty *
Proftpd-dfsg Ubuntu upstream *

References