id: CVE-2023-51713 info: name: ProFTPD < 1.3.8a - DoS via Out-of-Bounds Read author: pussycat0x severity: high description: | ProFTPD versions before 1.3.8a contain a one-byte out-of-bounds read vulnerability in the make_ftp_cmd function within main.c. This vulnerability can lead to a daemon crash, causing denial of service. impact: | Attackers can crash the ProFTPD daemon by triggering an out-of-bounds read in the make_ftp_cmd function, causing service disruption and denying legitimate users access to FTP services. remediation: | Upgrade to ProFTPD version 1.3.8a or later that fixes the out-of-bounds read vulnerability in the make_ftp_cmd function. reference: - https://github.com/proftpd/proftpd/blob/1.3.8/NEWS classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H cvss-score: 7.5 cve-id: CVE-2023-51713 cwe-id: CWE-125 epss-score: 0.04249 epss-percentile: 0.9 cpe: cpe:2.3:a:proftpd:proftpd:*:*:*:*:*:*:*:* metadata: verified: true max-request: 1 vendor: proftpd product: proftpd shodan-query: - product:"proftpd" - cpe:"cpe:2.3:a:proftpd:proftpd" tags: cve,cve2023,network,ftp,proftpd,tcp,passive,vuln tcp: - inputs: - data: 00000000 type: hex host: - "{{Hostname}}" port: 21 read-size: 1024 matchers: - type: dsl dsl: - "contains(raw, 'ProFTPD')" - "compare_versions(version, '< 1.3.8a')" condition: and extractors: - type: regex group: 1 name: version regex: - "ProFTPD ([0-9.a-z]+)" # digest: 4a0a0047304502205267f4d8ce087f0665f3e31ba2a9686512ab952fecba005d5a6faee52fcb4909022100f03a626d6cb9cc28e3d3f8109508052df9c5ae1259b28630aee43fddfece6619:922c64590222798bb761d5b6d8e72950