CVE-2010-4652
EPSS 6.0%
Description
Heap-based buffer overflow in the sql_prepare_where function (contrib/mod_sql.c) in ProFTPD before 1.3.3d, when mod_sql is enabled, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted username containing substitution tags, which are not properly handled during construction of an SQL query.
How to fix CVE-2010-4652
To remediate CVE-2010-4652, upgrade the affected package to a fixed version below.
- Debian/proftpd-dfsg—upgrade to 1.3.3a-6 or later
Is CVE-2010-4652 being exploited?
Moderate — EPSS is 6.0%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, < 1.3.3a-6