LightFTP 2.3.1 contains a residual race condition vulnerability (an incomplete fix for CVE-2024-11144) in the worker_thread_cleanup() function of ftpserv.c that allows remote unauthenticated attacker…
Medium CVSS 5.9
Summary
LightFTP 2.3.1 contains a residual race condition vulnerability (an incomplete fix for CVE-2024-11144) in the worker_thread_cleanup() function of ftpserv.c that allows remote unauthenticated attackers to destabilize or crash the daemon by triggering unsynchronized access to shared per-connection state without holding the required mutex lock. Attackers can send a data-transfer command such as LIST followed immediately by ABOR to exploit the missing synchronization on shared context and detached …
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Sources
- NVD DATABASE
Original Links
- https://github.com/zeroscience/tuktam#real-world-case-study-lightftp-cve-2024-11144
- https://www.vulncheck.com/advisories/lightftp-race-condition-dos-via-worker-thread-cleanup
- https://github.com/zeroscience/tuktam#real-world-case-study-lightftp-cve-2024-11144
Timeline
- nvd_ingest NVD