yocto ▾
›
scarthgap ▾
›
vulnerability
›
CVE-2023-51713
Component Overview
Vulnerability Overview
Name
CVE-2023-51713
Source
NVD (
link
)
Debian (
link
)
Description
make_ftp_cmd in main.c in ProFTPD before 1.3.8a has a one-byte out-of-bounds read, and daemon crash, because of mishandling of quote/backslash semantics.
CWEs
CWE-125
Published Date
Dec 22, 2023
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://github.com/proftpd/proftpd/blob/1.3.8/NEWS
Release Notes
https://github.com/proftpd/proftpd/issues/1683
Exploit
https://github.com/proftpd/proftpd/issues/1683#issuecomment-1712887554
Exploit
https://github.com/proftpd/proftpd/blob/1.3.8/NEWS
Release Notes
https://github.com/proftpd/proftpd/issues/1683
Exploit
https://github.com/proftpd/proftpd/issues/1683#issuecomment-1712887554
Exploit
Analysis
#
Affected Component
Analysis
proftpd
Exploitable
Vulnerability Rating
#
7.5
CVSSv31
Others affected components
#
Name
Project
Project Version
Version
Status
proftpd
buildroot
2025.02.x
1.3.8d
Not Affected
proftpd
buildroot
master
1.3.9a
Not Affected
proftpd
yocto
kirkstone
1.3.7c
Exploitable
proftpd
yocto
master
1.3.9b
Not Affected