An issue was discovered in tls_verify_crl in ProFTPD before 1.3.6. Direct dereference of a NULL pointer (a variable initialized to NULL) leads to a crash when validating the certificate of a client connecting to the server in a TLS client/server mutual-authentication setup.
A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Proftpd | Proftpd | * | 1.3.6 (excluding) |
Proftpd-dfsg | Ubuntu | bionic | * |
Proftpd-dfsg | Ubuntu | trusty | * |
Proftpd-dfsg | Ubuntu | xenial | * |