VYPR
High severity8.8NVD Advisory· Published Jul 20, 2026· Updated Jul 30, 2026

CVE-2026-63090

CVE-2026-63090

Description

ProFTPD before 1.3.9c and 1.3.10rc3 contains a heap-based buffer overflow vulnerability in the mod_sftp module that allows authenticated low-privilege attackers to achieve arbitrary code execution by sending crafted SFTP packet fragments exceeding the 16 KB reassembly buffer in the fxp.c component. Attackers can supply oversized fragments to trigger an incorrectly conditioned reallocation, corrupt pool freelist metadata, overwrite the root_fs BSS global pointer to reference a fake filesystem struct, and redirect pr_fsio_stat() to system() via a crafted RENAME request.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • Proftpd/Proftpd4 versions
    cpe:2.3:a:proftpd:proftpd:*:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:proftpd:proftpd:*:*:*:*:*:*:*:*range: <1.3.9c
    • cpe:2.3:a:proftpd:proftpd:1.3.10:rc1:*:*:*:*:*:*
    • cpe:2.3:a:proftpd:proftpd:1.3.10:rc2:*:*:*:*:*:*
    • (no CPE)range: <1.3.9c, <1.3.10rc3

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.