CVE-2017-15271 describes a remotely triggerable use-after-free vulnerability in the SFTP component of PSFTPd 10.0.4 Build 729, affecting psftp and psftpd products. This flaw, rated Medium severity (CVSS 5.9), allows unauthenticated attackers to cause a denial-of-service by sending a crafted SSH identification string, leading to a NULL pointer dereference and subsequent use-after-free during connection cleanup. While not actively exploited in the wild and lacking Metasploit or Nuclei modules, an ExploitDB entry (EDB-43144) confirms exploitability, though there is minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
10.0.4CPE matchmatch criteria | cpe:2.3:a:psftp:psftpd:10.0.4:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.