HIGH
An issue was discovered in Pure-FTPd 1.0.49
Published Feb 26, 2020
7.5
HIGHCVSS 3.1
EPSS 6.01%
Description
An issue was discovered in Pure-FTPd 1.0.49. An uninitialized pointer vulnerability has been detected in the diraliases linked list. When the *lookup_alias(const char alias) or print_aliases(void) function is called, they fail to correctly detect the end of the linked list and try to access a non-existent list member. This is related to init_aliases in diraliases.c.
Affected products
No data.
Configuration 2
- 8.0
Configuration 3
OR
- 7.0
- 8.0
- 30
- 31
- 32
Configuration 4
- 8.0
Configuration 5
- 16.04
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (8)
- https://github.com/jedisct1/pure-ftpd/commit/8d0d42542e2cb7a56d645fbe4d0ef436e38bcefa x_refsource_MISCPatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/02/msg00029.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/22P44PECZWNDP7CMBL7NRBMNFS73C5Z2/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/B5NSUDWXZVWUCL6R2PTX3KBB42Z62CA5/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U5DBVHJCXWRSJPNJQCJQCKZF6ZDPZCKA/ vendor-advisoryx_refsource_FEDORA
- https://security.gentoo.org/glsa/202003-54 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://usn.ubuntu.com/4515-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.pureftpd.org/project/pure-ftpd/news/ x_refsource_MISCVendor Advisory
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Feb 26, 2020
Updated Aug 4, 2024
Reserved Feb 19, 2020
Link CVE-2020-9274
CISA Vulnrichment
Updated n/a