Junglewise Threat Intelligence

CVE-2010-20103: ProFTPD malicious backdoor in source distribution

CVE-2010-20103 · Severity: critical · CVSS 9.8 · Published 2025-08-20

Technologies: Proftpd. Vendors: Proftpd.

Executive brief

ProFTPD is a widely used open-source file transfer server for Linux and Unix systems. A malicious backdoor was discovered in the official software download files distributed in late 2010, which allows an attacker to take complete control of the server. By sending a specific hidden command, an unauthorized person can remotely execute any instruction on the host computer with the highest possible privileges (root), potentially leading to data theft or full system compromise.

Technical details

A supply chain attack resulted in a malicious backdoor being embedded in the official ProFTPD 1.3.3c source archives (proftpd-1.3.3c.tar.gz and .bz2). The backdoor implements a hidden FTP command trigger that, when received by the daemon, bypasses authentication and executes arbitrary shell commands via a system call with root privileges. The vulnerability is reachable over the network without any prior authentication or user interaction. Security engineers should ensure that any installations from that period have been replaced with verified, clean versions of the software (1.3.3c or later maintenance releases).

Affected products

  • ProFTPD Project ProFTPD (Professional FTP Daemon) 1.3.3c

Timeline

  • 2010-11-28: disclosed: Backdoored source distributed starting this date
  • 2010-12-02: patched: Backdoored source removed from distribution sites
  • 2011-01-04: advisory: Check Point published third-party advisory
  • 2025-08-20: advisory: NVD publication date for CVE-2010-20103

References

Related threats