Junglewise Threat Intelligence

CVE-2026-63091: ProFTPD mod_sftp integer overflow in SCP size-record parser

CVE-2026-63091 · Severity: medium · CVSS 6.5 · Published 2026-07-20

Technologies: ProFTPD Project Proftpd.

Executive brief

ProFTPD, a widely used file transfer server, contains a security flaw in its SFTP module. An authenticated user with low privileges can trick the server into leaking its own internal memory during a file upload. This leaked information can be used to bypass security protections (like ASLR), making it easier for attackers to launch more severe attacks against the server.

Technical details

A signed integer overflow exists in the mod_sftp module's SCP size-record parser within ProFTPD. By sending a crafted file size value of UINT64_MAX, an authenticated attacker triggers a negative off_t value. When this value is subsequently converted to a uint32_t, it results in a massive (approx. 4GB) read length. This forces the server to read beyond the intended SSH channel data and write process memory—including libc, libcrypto, and PIE pointers—into the uploaded file. This memory disclosure allows attackers to calculate randomized base addresses, effectively bypassing ASLR. The issue is fixed in versions 1.3.9c and 1.3.10rc3.

Affected products

  • ProFTPD Project ProFTPD before 1.3.9c, 1.3.10rc1 to 1.3.10rc3

Timeline

  • 2026-07-01: patched: Fix merged into master branch via PR 2201
  • 2026-07-07: advisory: Release of v1.3.10rc3-3
  • 2026-07-08: advisory: Release of v1.3.9c
  • 2026-07-20: disclosed: NVD publication date

References