High severity7.5NVD Advisory· Published Oct 21, 2019· Updated Jun 17, 2026
CVE-2019-18217
CVE-2019-18217
Description
ProFTPD before 1.3.6b and 1.3.7rc before 1.3.7rc2 allows remote unauthenticated denial-of-service due to incorrect handling of overly long commands because main.c in a child process enters an infinite loop.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
14cpe:2.3:a:proftpd:proftpd:*:*:*:*:*:*:*:*+ 8 more
- cpe:2.3:a:proftpd:proftpd:*:*:*:*:*:*:*:*range: <=1.3.5
- cpe:2.3:a:proftpd:proftpd:1.3.6:-:*:*:*:*:*:*
- cpe:2.3:a:proftpd:proftpd:1.3.6:a:*:*:*:*:*:*
- cpe:2.3:a:proftpd:proftpd:1.3.6:rc1:*:*:*:*:*:*
- cpe:2.3:a:proftpd:proftpd:1.3.6:rc2:*:*:*:*:*:*
- cpe:2.3:a:proftpd:proftpd:1.3.6:rc3:*:*:*:*:*:*
- cpe:2.3:a:proftpd:proftpd:1.3.6:rc4:*:*:*:*:*:*
- cpe:2.3:a:proftpd:proftpd:1.3.7:rc1:*:*:*:*:*:*
- (no CPE)range: <1.3.6b, <1.3.7rc2
- ProFTPD/ProFTPDdescription
- osv-coords4 versionspkg:rpm/opensuse/proftpd&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/proftpd&distro=openSUSE%20Tumbleweedpkg:rpm/suse/proftpd&distro=SUSE%20Package%20Hub%2015pkg:rpm/suse/proftpd&distro=SUSE%20Package%20Hub%2015%20SP1
< 1.3.6b-bp151.4.6.2+ 3 more
- (no CPE)range: < 1.3.6b-bp151.4.6.2
- (no CPE)range: < 1.3.6e-1.10
- (no CPE)range: < 1.3.6b-bp151.4.6.2
- (no CPE)range: < 1.3.6b-bp151.4.6.2
Patches
Vulnerability mechanics
References
14- github.com/proftpd/proftpd/issues/846nvdExploitIssue TrackingThird Party Advisory
- github.com/proftpd/proftpd/blob/1.3.6/NEWSnvdRelease NotesThird Party Advisory
- github.com/proftpd/proftpd/blob/1.3.6/RELEASE_NOTESnvdRelease NotesThird Party Advisory
- github.com/proftpd/proftpd/blob/master/NEWSnvdRelease NotesThird Party Advisory
- github.com/proftpd/proftpd/blob/master/RELEASE_NOTESnvdRelease NotesThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2020-01/msg00009.htmlnvd
- cert-portal.siemens.com/productcert/pdf/ssa-940889.pdfnvd
- lists.debian.org/debian-lts-announce/2019/10/msg00036.htmlnvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NJDQRVZTILBX4BUCTIRKP2WBHDHDCJR5/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RB2FPAWDWXT5ALAFIC5Y3RSEMXSFL6H2/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YLRPYEEMQJVAXO2SXRGOQ4HBFEEPCNXG/nvd
- seclists.org/bugtraq/2019/Nov/7nvd
- security.gentoo.org/glsa/202003-35nvd
- www.debian.org/security/2019/dsa-4559nvd
News mentions
0No linked articles in our index yet.