漏洞描述
ProFTPD versions before 1.3.6b and various pre-release versions (1.3.7rc before 1.3.7rc2) are vulnerable to remote unauthenticated denial of service. The vulnerability occurs when processing overly long commands, causing an infinite loop in a child process that can crash the server.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
lists.opensuse.orghttp://lists.opensuse.org/opensuse-security-announce/2020-01/msg00009.html↗cert-portal.siemens.comhttps://cert-portal.siemens.com/productcert/pdf/ssa-940889.pdf↗github.comhttps://github.com/proftpd/proftpd/blob/1.3.6/NEWS↗github.comhttps://github.com/proftpd/proftpd/blob/1.3.6/RELEASE_NOTES↗github.comhttps://github.com/proftpd/proftpd/blob/master/NEWS↗