UBUNTU-CVE-2023-51713
High
UBUNTU-CVE-2023-51713
make_ftp_cmd in main.c in ProFTPD before 1.3.8a has a one-byte out-of-bounds read, and daemon crash, because of mishandling of quote/backslash semantics.
Exploit probability
Not scored
Published
December 22, 2023
Required by
Not available
Last source change
April 22, 2026
02 / AFFECTED SOFTWARE
Affected packages
4 explicit affected versions
2 explicit affected versions
3 explicit affected versions
2 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Open Source Vulnerabilities
UBUNTU-CVE-2023-51713
View original source
make_ftp_cmd in main.c in ProFTPD before 1.3.8a has a one-byte out-of-bounds read, and daemon crash, because of mishandling of quote/backslash semantics.
05 / REFERENCES
Further evidence
- https://github.com/proftpd/proftpd/commit/1376d8ccc0966d1ce9a1c76b32c6a9ca61bbe67f
- https://github.com/proftpd/proftpd/commit/97bbe68363ccf2de0c07f67170ec64a8b4d62592
- https://ubuntu.com/security/CVE-2023-51713
- https://ubuntu.com/security/notices/USN-7297-1
- https://www.cve.org/CVERecord?id=CVE-2023-51713