ProFTPD Buffer Overflow Vulnerability Allowing Arbitrary Code Execution and Denial-of-Service

Vulnerability

A buffer overflow vulnerability has been identified in ProFTPD version 1.3.7a+dfsg-12+deb11u5. This vulnerability allows remote attackers to execute arbitrary code and can lead to a denial-of-service condition on the FTP service. The issue arises when a maliciously crafted message is sent to the ProFTPD service port, causing the FTP service to crash.

Impact

Exploitation of this vulnerability allows for arbitrary code execution on the server where ProFTPD is running. Additionally, it causes a denial-of-service condition by crashing the FTP service, disrupting file transfer operations.

Reproduction

The vulnerability can be reproduced by sending a specially crafted message to the ProFTPD service port. This can be done using a network tool or script that allows for the manipulation of the message content. The crafted message should exploit the buffer overflow vulnerability, leading to the execution of arbitrary code on the server.

Remediation

Users can upgrade to ProFTPD version 1.3.7a+dfsg-12+deb11u5 to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
6.4
impact
10.0
exploitability
8.6
remediation
7.7
relevance
0.0
threat
1.7
urgency
2.9
incentive
10.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.