An issue was discovered in Pure-FTPd 1.0.49. An uninitialized pointer vulnerability has been detected in the diraliases linked list. When the *lookup_alias(const char alias) or print_aliases(void) function is called, they fail to correctly detect the end of the linked list and try to access a non-existent list member. This is related to init_aliases in diraliases.c.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade pure-ftpd | Aug 22, 2024 | Feb 26, 2020 |
| Debian | — | Upgrade pure-ftpd | Mar 2, 2020 | Feb 26, 2020 |
| Gentoo Linux | — | Upgrade net-ftp/pure-ftpd. | Mar 27, 2020 | Feb 26, 2020 |
| Ubuntu | — | Upgrade pure-ftpdUpgrade pure-ftpd-mysqlUpgrade pure-ftpd-commonUpgrade pure-ftpd-ldapUpgrade pure-ftpd-postgresql | Sep 18, 2020 | Feb 26, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub