← Back

CVE-2019-19270

nvd nist
Published: Nov 26, 2019Modified: Jun 17, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

An issue was discovered in tls_verify_crl in ProFTPD through 1.3.6b. Failure to check for the appropriate field of a CRL entry (checking twice for subject, rather than once for subject and once for issuer) prevents some valid CRLs from being taken into account, and can allow clients whose certificates have been revoked to proceed with a connection to the server.

Affected (6)

1 product
Proftpd
1 product
Fedora
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Proftpd
Up to 1.3.5
Version 1.3.6
Version 1.3.6 alpha
Version 1.3.6 beta
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 30
Version 31

Timeline

No history available yet.