ProFTPd: Multiple vulnerabilities Multiple vulnerabilities have been found in ProFTPd, the worst of which may lead to arbitrary code execution. proftpd 2020-03-16 2020-03-16 699520 701814 710730 remote 1.3.6c 1.3.6c

ProFTPD is an advanced and very configurable FTP server.

Multiple vulnerabilities have been discovered in ProFTPd. Please review the CVE identifiers referenced below for details.

A remote attacker, by interrupting the data transfer channel, could possibly execute arbitrary code with the privileges of the process or cause a Denial of Service condition.

There is no known workaround at this time.

All ProFTPd users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=net-ftp/proftpd-1.3.6c"
CVE-2019-18217 CVE-2019-19269 CVE-2020-9272 CVE-2020-9273 BlueKnight whissi