Total vulnerabilities in the database
An issue was discovered in tls_verify_crl in ProFTPD through 1.3.6b. A dereference of a NULL pointer may occur. This pointer is returned by the OpenSSL sk_X509_REVOKED_value() function when encountering an empty CRL installed by a system administrator. The dereference occurs when validating the certificate of a client connecting to the server in a TLS client/server mutual-authentication setup.
Software | From | Fixed in |
---|---|---|
proftpd / proftpd | 1.3.6-rc3 | 1.3.6-rc3.x |
proftpd / proftpd | 1.3.6-rc2 | 1.3.6-rc2.x |
proftpd / proftpd | 1.3.6-rc1 | 1.3.6-rc1.x |
proftpd / proftpd | 1.3.6-rc4 | 1.3.6-rc4.x |
proftpd / proftpd | 1.3.6 | 1.3.6.x |
proftpd / proftpd | 1.3.6-alpha | 1.3.6-alpha.x |
proftpd / proftpd | 1.3.6-beta | 1.3.6-beta.x |
proftpd / proftpd | - | 1.3.5e.x |
fedoraproject / fedora | 30 | 30.x |
fedoraproject / fedora | 31 | 31.x |
debian / debian_linux | 8.0 | 8.0.x |