Critical vulnerability CVE-2019-12815 in ProFTPd

A critical vulnerability (CVE-2019-12815) has been discovered in ProFTPd (a popular FTP server). Exploitation allows copying files within the server without authentication using the "site cpfr" and "site cpto" commands, including on servers with anonymous access.

The vulnerability is caused by incorrect access control checks on read and write permissions (Limit READ and Limit WRITE) in the mod_copy module, which is used by default and included in ProFTPd packages for most distributions.

All current versions across all distributions are affected, except for Fedora. A fix is currently available in the form of a patch. As a temporary workaround, it is recommended to disable mod_copy.

Source: linux.org.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster