← Back

CVE-2026-63090

nvd nist
Published: Jul 20, 2026Modified: Jul 30, 2026

JSON object

Loading...
8.7
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Show more
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: disclosure@vulncheck.com (Secondary)

Description

ProFTPD before 1.3.9c and 1.3.10rc3 contains a heap-based buffer overflow vulnerability in the mod_sftp module that allows authenticated low-privilege attackers to achieve arbitrary code execution by sending crafted SFTP packet fragments exceeding the 16 KB reassembly buffer in the fxp.c component. Attackers can supply oversized fragments to trigger an incorrectly conditioned reallocation, corrupt pool freelist metadata, overwrite the root_fs BSS global pointer to reference a fake filesystem struct, and redirect pr_fsio_stat() to system() via a crafted RENAME request.

Affected (3)

Products: Proftpd: Proftpd
1 product
Proftpd
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Proftpd
Before 1.3.9c
Version 1.3.10 rc1
Version 1.3.10 rc2

References (6)

Source: disclosure@vulncheck.com
Release Notes
Source: disclosure@vulncheck.com
Issue Tracking
Source: disclosure@vulncheck.com
ProductRelease Notes
Source: disclosure@vulncheck.com
ProductRelease Notes
Source: disclosure@vulncheck.com
Third Party AdvisoryPatchRelease Notes

Timeline

No history available yet.