Executive brief
ProFTPD, a widely used file transfer server, contains a security flaw in its SFTP module. An authenticated user with low privileges can trick the server into leaking its own internal memory during a file upload. This leaked information can be used to bypass security protections (like ASLR), making it easier for attackers to launch more severe attacks against the server.
Technical details
A signed integer overflow exists in the mod_sftp module's SCP size-record parser within ProFTPD. By sending a crafted file size value of UINT64_MAX, an authenticated attacker triggers a negative off_t value. When this value is subsequently converted to a uint32_t, it results in a massive (approx. 4GB) read length. This forces the server to read beyond the intended SSH channel data and write process memory—including libc, libcrypto, and PIE pointers—into the uploaded file. This memory disclosure allows attackers to calculate randomized base addresses, effectively bypassing ASLR. The issue is fixed in versions 1.3.9c and 1.3.10rc3.
Affected products
- ProFTPD Project ProFTPD before 1.3.9c, 1.3.10rc1 to 1.3.10rc3
Timeline
- 2026-07-01: patched: Fix merged into master branch via PR 2201
- 2026-07-07: advisory: Release of v1.3.10rc3-3
- 2026-07-08: advisory: Release of v1.3.9c
- 2026-07-20: disclosed: NVD publication date
References
- https://github.com/proftpd/proftpd/blob/master/RELEASE_NOTES
- https://github.com/proftpd/proftpd/commit/b9b7dde1bcd74bc23366484d53856b67b8d6d95e
- https://github.com/proftpd/proftpd/pull/2201
- https://github.com/proftpd/proftpd/releases/tag/v1.3.10rc3-3
- https://github.com/proftpd/proftpd/releases/tag/v1.3.9c
- https://www.vulncheck.com/advisories/proftpd-mod-sftp-signed-integer-overflow-via-scp-size-record-parser