First published: Wed Feb 26 2020(Updated: )
An issue was discovered in Pure-FTPd 1.0.49. An uninitialized pointer vulnerability has been detected in the diraliases linked list. When the *lookup_alias(const char alias) or print_aliases(void) function is called, they fail to correctly detect the end of the linked list and try to access a non-existent list member. This is related to init_aliases in diraliases.c.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Pureftpd Pure-ftpd | <1.0.50 | |
Debian Debian Linux | =8.0 | |
Fedoraproject Extra Packages For Enterprise Linux | =7.0 | |
Fedoraproject Extra Packages For Enterprise Linux | =8.0 | |
Fedoraproject Fedora | =30 | |
Fedoraproject Fedora | =31 | |
Fedoraproject Fedora | =32 | |
Canonical Ubuntu Linux | =16.04 | |
ubuntu/pure-ftpd | <1.0.49-4 | 1.0.49-4 |
ubuntu/pure-ftpd | <1.0.36-3.2+ | 1.0.36-3.2+ |
debian/pure-ftpd | 1.0.49-4.1 1.0.50-2.1 1.0.50-2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-9274 is a vulnerability found in Pure-FTPd 1.0.49 that allows for an uninitialized pointer exploit.
The severity of CVE-2020-9274 is high with a CVSS score of 7.5.
The affected software versions include Pure-FTPd 1.0.49-4.1, 1.0.50-2.1, 1.0.49-4, and 1.0.36-3.2+.
To fix CVE-2020-9274, update to a patched version of Pure-FTPd, such as 1.0.49-4.1 or 1.0.50-2.1.
More information about CVE-2020-9274 can be found on the following references: [link1], [link2], [link3]