Impact
ProFTPD before 1.3.9c and 1.3.10rc3 contains a heap‑based buffer overflow in the mod_sftp module. The vulnerability is triggered when the server reassembles oversized SFTP packet fragments that exceed a 16 KB buffer within the fxp.c component. An attacker with low‑privilege SFTP credentials can craft fragmented packets that cause an incorrectly conditioned reallocation, corrupt freelist metadata, overwrite the root_fs BSS global pointer to reference a fake filesystem struct, and redirect a stat call to system() via a specially crafted RENAME request. This chain of events allows the attacker to execute arbitrary code on the server, compromising confidentiality, integrity, and availability. Affected systems: All installations of ProFTPD older than version 1.3.9c or 1.3.10rc3 that have the mod_sftp module enabled are vulnerable. The flaw is documented in the ProFTPD project release notes and issue tracker. Users running the stable 1.3.9 or earlier, or those on the 1.3.10rc3 pre‑release branch without the patch, are affected. The high CVSS score indicates substantial potential damage. The EPSS score of less than 1% signals a very low but non‑zero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Because the attacker needs only low‑privilege credentials, the barrier to exploitation is low. While no public exploit is currently known, the potential for arbitrary code execution represents significant risk.
Affected Systems
ProFTPD versions older than 1.3.9c and 1.3.10rc3 with the mod_sftp module enabled.
Risk and Exploitability
The high CVSS score signals significant potential damage. The EPSS score of less than 1% indicates a very low but non‑zero probability of exploitation, although the exact likelihood remains uncertain, and no KEV listing reduces the visibility of public attacks. Nonetheless, the simplified attack path—authenticated low‑privilege SFTP packet manipulation—means that any exposed server can be abused if the vulnerable code is present.
OpenCVE Enrichment