CVE-2023-51713
Not scored
CVE-2023-51713
make_ftp_cmd in main.c in ProFTPD before 1.3.8a has a one-byte out-of-bounds read, and daemon crash, because of mishandling of quote/backslash semantics.
Exploit probability
4.2%
Published
December 22, 2023
Required by
Not available
Last source change
August 12, 2026
02 / AFFECTED SOFTWARE
Affected packages
18 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Open Source Vulnerabilities
CVE-2023-51713
View original source
make_ftp_cmd in main.c in ProFTPD before 1.3.8a has a one-byte out-of-bounds read, and daemon crash, because of mishandling of quote/backslash semantics.
05 / REFERENCES
Further evidence
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/51xxx/CVE-2023-51713.json
- https://github.com/proftpd/proftpd/blob/1.3.8/NEWS
- https://github.com/proftpd/proftpd/issues/1683
- https://github.com/proftpd/proftpd/issues/1683#issuecomment-1712887554
- https://lists.debian.org/debian-lts-announce/2024/11/msg00032.html
- https://nvd.nist.gov/vuln/detail/CVE-2023-51713