First published: Tue Dec 31 2019(Updated: )
In Pure-FTPd 1.0.49, a stack exhaustion issue was discovered in the listdir function in ls.c.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Pureftpd Pure-ftpd | =1.0.49 | |
Fedoraproject Fedora | =30 | |
Fedoraproject Fedora | =31 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-20176 is a vulnerability in Pure-FTPd 1.0.49 that allows for stack exhaustion in the listdir function in ls.c.
CVE-2019-20176 has a severity rating of 7.5 (high).
Pure-FTPd 1.0.49, Fedoraproject Fedora 30, and Fedoraproject Fedora 31 are affected by CVE-2019-20176.
To fix CVE-2019-20176, you should update Pure-FTPd to a version that includes the fix for the vulnerability.
You can find more information about CVE-2019-20176 at the following references: [Link 1](https://github.com/jedisct1/pure-ftpd/commit/aea56f4bcb9948d456f3fae4d044fd3fa2e19706), [Link 2](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AHZG5FPCRMCB6Z3L7FPICC6BZ5ZATFTO/), [Link 3](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PICL3U2J4EPGBLOE555Y5RAZTQL3WBBV/).