ProFTPD: Denial of service — GLSA 202009-11

A vulnerability in ProFTPD could lead to a Denial of Service condition.

Affected packages

net-ftp/proftpd on all architectures
Affected versions < 1.3.7a
Unaffected versions >= 1.3.7a

Background

ProFTPD is an advanced and very configurable FTP server.

Description

It was found that ProFTPD did not properly handle invalid SCP commands.

Impact

An authenticated remote attacker could issue invalid SCP commands, possibly resulting in a Denial of Service condition.

Workaround

There is no known workaround at this time.

Resolution

All ProFTPD users should upgrade to the latest version:

 # emerge --sync
 # emerge --ask --oneshot --verbose ">=net-ftp/proftpd-1.3.7a"
 

References

Release date
September 13, 2020

Latest revision
September 13, 2020: 1

Severity
low

Exploitable
local, remote

Bugzilla entries