CVE-2011-1137

Aliases:DEBIAN-CVE-2011-1137
Advisory lineage Upstream: 0 Downstream: 3
Modified
Published: 11 Mar 2011, 17:00
Last modified:06 Aug 2024, 22:14

Vulnerability Summary

Overall Risk (default)
medium
36/100
CVSS Score
5 MEDIUM
v2.0 (nvd)
EPSS Score
28.07% HIGH
28% probability +25.50%
KEV
Not listed
Ransomware
No reports
Public exploits
3 found
Dark Web
Not detected

Timeline

11 Mar 2011, 17:00
Published
Vulnerability first disclosed
06 Aug 2024, 22:14
Last Modified
Vulnerability information updated

Description

Integer overflow in the mod_sftp (aka SFTP) module in ProFTPD 1.3.3d and earlier allows remote attackers to cause a denial of service (memory consumption leading to OOM kill) via a malformed SSH message.

CVSS Metrics

  • v2.0•MEDIUM•Score: 5AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS Trends

Current EPSS score: 28.07%• Percentile: 98%

Techniques & Countermeasures

  • CWE-189•Numeric Errors

    Weaknesses in this category are related to improper calculation or conversion of numbers.

Affected Systems

  • debian•proftpd-dfsg

    < 1.3.3d-4 | < 1.3.3d-4 | < 1.3.3d-4 | < 1.3.3d-4

  • proftpd•proftpd

    ≤ 1.3.3 | 1.2.0 | 1.2.0:pre10 | 1.2.0:pre9 | 1.2.0:rc1 | 1.2.0:rc2 | 1.2.0:rc3 | 1.2.1 | 1.2.2 | 1.2.2:rc1 | 1.2.2:rc2 | 1.2.2:rc3 | 1.2.3 | 1.2.4 | 1.2.5 | 1.2.5:rc1 | 1.2.5:rc2 | 1.2.5:rc3 | 1.2.6 | 1.2.6:rc1 | 1.2.6:rc2 | 1.2.7 | 1.2.7:rc1 | 1.2.7:rc2 | 1.2.7:rc3 | 1.2.8 | 1.2.8:rc1 | 1.2.8:rc2 | 1.2.9 | 1.2.9:rc1 | 1.2.9:rc2 | 1.2.9:rc3 | 1.2.10 | 1.2.10:rc1 | 1.2.10:rc2 | 1.2.10:rc3 | 1.3.0 | 1.3.0:a | 1.3.0:rc1 | 1.3.0:rc2 | 1.3.0:rc3 | 1.3.0:rc4 | 1.3.0:rc5 | 1.3.1 | 1.3.1:rc1 | 1.3.1:rc2 | 1.3.1:rc3 | 1.3.2 | 1.3.2:a | 1.3.2:b | 1.3.2:c | 1.3.2:d | 1.3.2:e | 1.3.2:rc1 | 1.3.2:rc2 | 1.3.2:rc3 | 1.3.2:rc4 | 1.3.3 | 1.3.3:a | 1.3.3:b | 1.3.3:c | 1.3.3:rc1 | 1.3.3:rc2 | 1.3.3:rc3 | 1.3.3:rc4

References (18)