摘要:
An issue was discovered in tls_verify_crl in ProFTPD before 1.3.6. A wrong iteration variable, used when checking a client certificate against CRL entries (installed by a system administrator), can cause some CRL entries to be ignored, and can allow clients whose certificates have been revoked to proceed with a connection to the server.
安全等级: Low
公告ID: KylinSec-SA-2022-1208
发布日期: 2022年3月11日
关联CVE: CVE-2019-19271
An issue was discovered in tls_verify_crl in ProFTPD before 1.3.6. A wrong iteration variable, used when checking a client certificate against CRL entries (installed by a system administrator), can cause some CRL entries to be ignored, and can allow clients whose certificates have been revoked to proceed with a connection to the server.
cve名称 | 产品 | 组件 | 是否受影响 |
---|---|---|---|
CVE-2019-19271 | KY3.4-4A | proftpd | Unaffected |
CVE-2019-19271 | KY3.4-5 | proftpd | Unaffected |