Authenticated session crash via null pointer dereferences
Published Feb 6, 2025 · Updated Mar 2, 2025
NULL pointer dereferences in ProFTPD at commit 4017eff8 allow remote authenticated users to crash their own FTP session during data transfers. In modules/mod_ls.c, sendline reads session.d->outstrm and outputfiles writes tail->down without first ensuring those pointers are non-NULL. The upstream maintainer reproduced only per-session crashes after authentication, found no buffer overflow or code execution, and reports that other clients and connections remain unaffected.
Summary
What happened
NULL pointer dereferences in ProFTPD at commit 4017eff8 allow remote authenticated users to crash their own FTP session during data transfers. In modules/mod_ls.c, sendline reads session.d->outstrm and outputfiles writes tail->down without first ensuring those pointers are non-NULL. The upstream maintainer reproduced only per-session crashes after authentication, found no buffer overflow or code execution, and reports that other clients and connections remain unaffected.
The record
- CVE
- CVE-2024-57392
- Published
- Feb 6, 2025
- Updated
- Mar 2, 2025
- Vendor
- Unknown vendor
- Product
- Unknown product
- Classifications
- CWE-120
- Attack vector
- network
- Privileges
- authenticated
Timeline
How it unfolded
- Feb 6, 2025CVE publishedPublication date reported by the CVE source.
- Mar 2, 2025Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
What conditions does exploitation require?
What is affected?
Affected products and versions are unavailable in this record.
Published CVSS scores
CVSS describes severity. EPSS estimates exploitation probability.
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Weakness, pattern, technique
Public exploit references
- protocol_vul_repoduce ProFTPD test casesproof of concept · demonstrated
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo