CVE-2011-1137

Exp

Integer overflow in the mod_sftp (aka SFTP) module in ProFTPD 1.3.3d and earlier allows remote attackers to cause a denial of service (memory consumption leading to OOM kill) via a malformed SSH message.

Published: 2011-03-11 Last update: 2026-04-29 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2011-1137 is rated High Exploit Risk (66.6/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 3.45%). Core evidence: 4 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Public exploit references (Exploit-DB) for CVE-2011-1137

EDB-ID Source Kind Published Link
16129 exploit_db edb 2011-02-07 Exploit-DB ↗
nvd_ref exploit_tag Exploit-DB ↗
nvd_ref exploit_tag Exploit-DB ↗
nvd_ref exploit_tag Exploit-DB ↗

Exploit prediction scoring system (EPSS) score for CVE-2011-1137

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-06-04 2.57% 3.45% +0.88%
2 2025-12-28 3.85% 2.57% -1.28%
3 2025-12-27 3.85%

Full EPSS history (18 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2011-1137

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
5.0 2.0 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:L)
Exploitation conditions are straightforward and predictable.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:N)
No confidentiality impact.
Integrity impact (I:N)
No integrity impact.
Availability impact (A:P)
Partial availability impact.
10.0 2.9 [email protected]

Weakness enumeration for CVE-2011-1137

OS Trackers for CVE-2011-1137

vendor priority summary link
debian not yet assigned CVE-2011-1137 not yet assigned priority: Debian including 1 source packages (proftpd-dfsg), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. https://security-tracker.debian.org/tracker/CVE-2011-1137
gentoo high CVE-2011-1137: 1 GLSA(s) (201309-15), 1 atom(s) (net-ftp/proftpd); latest impact high. https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2011-1137
ubuntu medium CVE-2011-1137 medium priority: Ubuntu including 1 source packages (proftpd-dfsg), 8 status rows across 8 suites (dapper, hardy, karmic, lucid, maverick, natty, oneiric, upstream): not-affected 4, ignored 2, DNE 1, needs-triage 1. https://ubuntu.com/security/CVE-2011-1137

Affected software / configurations for CVE-2011-1137

Vendor Product Version Raw CPE
proftpd proftpd <= 1.3.3 cpe:2.3:a:proftpd:proftpd:*:d:*:*:*:*:*:*
proftpd proftpd 1.2.0 cpe:2.3:a:proftpd:proftpd:1.2.0:*:*:*:*:*:*:*
proftpd proftpd 1.2.0 cpe:2.3:a:proftpd:proftpd:1.2.0:pre10:*:*:*:*:*:*
proftpd proftpd 1.2.0 cpe:2.3:a:proftpd:proftpd:1.2.0:pre9:*:*:*:*:*:*
proftpd proftpd 1.2.0 cpe:2.3:a:proftpd:proftpd:1.2.0:rc1:*:*:*:*:*:*
proftpd proftpd 1.2.0 cpe:2.3:a:proftpd:proftpd:1.2.0:rc2:*:*:*:*:*:*
proftpd proftpd 1.2.0 cpe:2.3:a:proftpd:proftpd:1.2.0:rc3:*:*:*:*:*:*
proftpd proftpd 1.2.1 cpe:2.3:a:proftpd:proftpd:1.2.1:*:*:*:*:*:*:*
proftpd proftpd 1.2.2 cpe:2.3:a:proftpd:proftpd:1.2.2:*:*:*:*:*:*:*
proftpd proftpd 1.2.2 cpe:2.3:a:proftpd:proftpd:1.2.2:rc1:*:*:*:*:*:*
proftpd proftpd 1.2.2 cpe:2.3:a:proftpd:proftpd:1.2.2:rc2:*:*:*:*:*:*
proftpd proftpd 1.2.2 cpe:2.3:a:proftpd:proftpd:1.2.2:rc3:*:*:*:*:*:*
proftpd proftpd 1.2.3 cpe:2.3:a:proftpd:proftpd:1.2.3:*:*:*:*:*:*:*
proftpd proftpd 1.2.4 cpe:2.3:a:proftpd:proftpd:1.2.4:*:*:*:*:*:*:*
proftpd proftpd 1.2.5 cpe:2.3:a:proftpd:proftpd:1.2.5:*:*:*:*:*:*:*
proftpd proftpd 1.2.5 cpe:2.3:a:proftpd:proftpd:1.2.5:rc1:*:*:*:*:*:*
proftpd proftpd 1.2.5 cpe:2.3:a:proftpd:proftpd:1.2.5:rc2:*:*:*:*:*:*
proftpd proftpd 1.2.5 cpe:2.3:a:proftpd:proftpd:1.2.5:rc3:*:*:*:*:*:*
proftpd proftpd 1.2.6 cpe:2.3:a:proftpd:proftpd:1.2.6:*:*:*:*:*:*:*
proftpd proftpd 1.2.6 cpe:2.3:a:proftpd:proftpd:1.2.6:rc1:*:*:*:*:*:*
proftpd proftpd 1.2.6 cpe:2.3:a:proftpd:proftpd:1.2.6:rc2:*:*:*:*:*:*
proftpd proftpd 1.2.7 cpe:2.3:a:proftpd:proftpd:1.2.7:*:*:*:*:*:*:*
proftpd proftpd 1.2.7 cpe:2.3:a:proftpd:proftpd:1.2.7:rc1:*:*:*:*:*:*
proftpd proftpd 1.2.7 cpe:2.3:a:proftpd:proftpd:1.2.7:rc2:*:*:*:*:*:*
proftpd proftpd 1.2.7 cpe:2.3:a:proftpd:proftpd:1.2.7:rc3:*:*:*:*:*:*
proftpd proftpd 1.2.8 cpe:2.3:a:proftpd:proftpd:1.2.8:*:*:*:*:*:*:*
proftpd proftpd 1.2.8 cpe:2.3:a:proftpd:proftpd:1.2.8:rc1:*:*:*:*:*:*
proftpd proftpd 1.2.8 cpe:2.3:a:proftpd:proftpd:1.2.8:rc2:*:*:*:*:*:*
proftpd proftpd 1.2.9 cpe:2.3:a:proftpd:proftpd:1.2.9:*:*:*:*:*:*:*
proftpd proftpd 1.2.9 cpe:2.3:a:proftpd:proftpd:1.2.9:rc1:*:*:*:*:*:*
proftpd proftpd 1.2.9 cpe:2.3:a:proftpd:proftpd:1.2.9:rc2:*:*:*:*:*:*
proftpd proftpd 1.2.9 cpe:2.3:a:proftpd:proftpd:1.2.9:rc3:*:*:*:*:*:*
proftpd proftpd 1.2.10 cpe:2.3:a:proftpd:proftpd:1.2.10:*:*:*:*:*:*:*
proftpd proftpd 1.2.10 cpe:2.3:a:proftpd:proftpd:1.2.10:rc1:*:*:*:*:*:*
proftpd proftpd 1.2.10 cpe:2.3:a:proftpd:proftpd:1.2.10:rc2:*:*:*:*:*:*
proftpd proftpd 1.2.10 cpe:2.3:a:proftpd:proftpd:1.2.10:rc3:*:*:*:*:*:*
proftpd proftpd 1.3.0 cpe:2.3:a:proftpd:proftpd:1.3.0:*:*:*:*:*:*:*
proftpd proftpd 1.3.0 cpe:2.3:a:proftpd:proftpd:1.3.0:a:*:*:*:*:*:*
proftpd proftpd 1.3.0 cpe:2.3:a:proftpd:proftpd:1.3.0:rc1:*:*:*:*:*:*
proftpd proftpd 1.3.0 cpe:2.3:a:proftpd:proftpd:1.3.0:rc2:*:*:*:*:*:*
proftpd proftpd 1.3.0 cpe:2.3:a:proftpd:proftpd:1.3.0:rc3:*:*:*:*:*:*
proftpd proftpd 1.3.0 cpe:2.3:a:proftpd:proftpd:1.3.0:rc4:*:*:*:*:*:*
proftpd proftpd 1.3.0 cpe:2.3:a:proftpd:proftpd:1.3.0:rc5:*:*:*:*:*:*
proftpd proftpd 1.3.1 cpe:2.3:a:proftpd:proftpd:1.3.1:*:*:*:*:*:*:*
proftpd proftpd 1.3.1 cpe:2.3:a:proftpd:proftpd:1.3.1:rc1:*:*:*:*:*:*
proftpd proftpd 1.3.1 cpe:2.3:a:proftpd:proftpd:1.3.1:rc2:*:*:*:*:*:*
proftpd proftpd 1.3.1 cpe:2.3:a:proftpd:proftpd:1.3.1:rc3:*:*:*:*:*:*
proftpd proftpd 1.3.2 cpe:2.3:a:proftpd:proftpd:1.3.2:*:*:*:*:*:*:*
proftpd proftpd 1.3.2 cpe:2.3:a:proftpd:proftpd:1.3.2:a:*:*:*:*:*:*
proftpd proftpd 1.3.2 cpe:2.3:a:proftpd:proftpd:1.3.2:b:*:*:*:*:*:*
proftpd proftpd 1.3.2 cpe:2.3:a:proftpd:proftpd:1.3.2:c:*:*:*:*:*:*
proftpd proftpd 1.3.2 cpe:2.3:a:proftpd:proftpd:1.3.2:d:*:*:*:*:*:*
proftpd proftpd 1.3.2 cpe:2.3:a:proftpd:proftpd:1.3.2:e:*:*:*:*:*:*
proftpd proftpd 1.3.2 cpe:2.3:a:proftpd:proftpd:1.3.2:rc1:*:*:*:*:*:*
proftpd proftpd 1.3.2 cpe:2.3:a:proftpd:proftpd:1.3.2:rc2:*:*:*:*:*:*
proftpd proftpd 1.3.2 cpe:2.3:a:proftpd:proftpd:1.3.2:rc3:*:*:*:*:*:*
proftpd proftpd 1.3.2 cpe:2.3:a:proftpd:proftpd:1.3.2:rc4:*:*:*:*:*:*
proftpd proftpd 1.3.3 cpe:2.3:a:proftpd:proftpd:1.3.3:*:*:*:*:*:*:*
proftpd proftpd 1.3.3 cpe:2.3:a:proftpd:proftpd:1.3.3:a:*:*:*:*:*:*
proftpd proftpd 1.3.3 cpe:2.3:a:proftpd:proftpd:1.3.3:b:*:*:*:*:*:*
proftpd proftpd 1.3.3 cpe:2.3:a:proftpd:proftpd:1.3.3:c:*:*:*:*:*:*
proftpd proftpd 1.3.3 cpe:2.3:a:proftpd:proftpd:1.3.3:rc1:*:*:*:*:*:*
proftpd proftpd 1.3.3 cpe:2.3:a:proftpd:proftpd:1.3.3:rc2:*:*:*:*:*:*
proftpd proftpd 1.3.3 cpe:2.3:a:proftpd:proftpd:1.3.3:rc3:*:*:*:*:*:*
proftpd proftpd 1.3.3 cpe:2.3:a:proftpd:proftpd:1.3.3:rc4:*:*:*:*:*:*

References for CVE-2011-1137

URL Tags
http://bugs.proftpd.org/show_bug.cgi?id=3586 Patch
http://bugs.proftpd.org/show_bug.cgi?id=3587
http://lists.fedoraproject.org/pipermail/package-announce/2011-April/058344.html
http://lists.fedoraproject.org/pipermail/package-announce/2011-April/058356.html
http://proftp.cvs.sourceforge.net/viewvc/proftp/proftpd/contrib/mod_sftp/mod_sftp.c?r1=1.29.2.1&r2=1.29.2.2 Patch
http://proftp.cvs.sourceforge.net/viewvc/proftp/proftpd/contrib/mod_sftp/packet.c?r1=1.14.2.2&r2=1.14.2.3 Vendor Advisory
http://proftp.cvs.sourceforge.net/viewvc/proftp/proftpd/contrib/mod_sftp/packet.h?r1=1.3&r2=1.3.2.1 Vendor Advisory
http://secunia.com/advisories/43234 Vendor Advisory
http://secunia.com/advisories/43635 Vendor Advisory
http://secunia.com/advisories/43978
http://slackware.com/security/viewer.php?l=slackware-security&y=2011&m=slackware-security.485806
http://www.debian.org/security/2011/dsa-2185
http://www.exploit-db.com/exploits/16129/ Exploit
http://www.securityfocus.com/bid/46183 Exploit
http://www.vupen.com/english/advisories/2011/0617 Vendor Advisory
http://www.vupen.com/english/advisories/2011/0857
https://bugzilla.redhat.com/show_bug.cgi?id=681718 Exploit Patch
cvelogic Threat Intelligence