Candidate: CVE-2019-19272 PublicDate: 2019-11-26 04:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19272 https://github.com/proftpd/proftpd/issues/858 Description: An issue was discovered in tls_verify_crl in ProFTPD before 1.3.6. Direct dereference of a NULL pointer (a variable initialized to NULL) leads to a crash when validating the certificate of a client connecting to the server in a TLS client/server mutual-authentication setup. Ubuntu-Description: Notes: Mitigation: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] Patches_proftpd-dfsg: upstream_proftpd-dfsg: needs-triage precise/esm_proftpd-dfsg: DNE trusty_proftpd-dfsg: ignored (out of standard support) trusty/esm_proftpd-dfsg: DNE xenial_proftpd-dfsg: ignored (end of standard support, was needs-triage) bionic_proftpd-dfsg: needs-triage disco_proftpd-dfsg: not-affected (1.3.6-4) eoan_proftpd-dfsg: not-affected (1.3.6-6build2) focal_proftpd-dfsg: not-affected (1.3.6-6build2) groovy_proftpd-dfsg: not-affected (1.3.6-6build2) hirsute_proftpd-dfsg: not-affected (1.3.6-6build2) impish_proftpd-dfsg: not-affected (1.3.6-6build2) jammy_proftpd-dfsg: not-affected (1.3.6-6build2) devel_proftpd-dfsg: not-affected (1.3.6-6build2)