7.5

CVE-2019-18217

Exploit
ProFTPD before 1.3.6b and 1.3.7rc before 1.3.7rc2 allows remote unauthenticated denial-of-service due to incorrect handling of overly long commands because main.c in a child process enters an infinite loop.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ProftpdProftpd Version <= 1.3.5
ProftpdProftpd Version1.3.6 Update-
ProftpdProftpd Version1.3.6 Updatea
ProftpdProftpd Version1.3.6 Updaterc1
ProftpdProftpd Version1.3.6 Updaterc2
ProftpdProftpd Version1.3.6 Updaterc3
ProftpdProftpd Version1.3.6 Updaterc4
ProftpdProftpd Version1.3.7 Updaterc1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.31% 0.87
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.