FlawAtlas
Search the atlas
SUSE-SU-2025:1028-1 Not scored

Security update for proftpd

This update for proftpd fixes the following issues: - CVE-2024-57392: Fixed null pointer dereference vulnerability by sending a maliciously crafted message (bsc#1238143). - CVE-2024-48651: Fixed supplemental group inheritance granting unintended access to GID 0 (bsc#1238141).

Exploit probability Not scored
Published March 26, 2025
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Enterprise Module for Server Applications 15 SP6 proftpd
openSUSE:Leap 15.6 proftpd

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2025:1028-1

This update for proftpd fixes the following issues: - CVE-2024-57392: Fixed null pointer dereference vulnerability by sending a maliciously crafted message (bsc#1238143). - CVE-2024-48651: Fixed supplemental group inheritance granting unintended access to GID 0 (bsc#1238141).

View original source

05 / REFERENCES

Further evidence