CVE-2020-9274: High severity pureftpd Pure-FTPd vulnerability
An issue was discovered in Pure-FTPd 1.0.49. An uninitialized pointer vulnerability has been detected in the diraliases linked list. When the lookupalias(const char alias) or printaliases(void) function is called, they fail to correctly detect the end of the linked list and try to access a non-existent list member. This is related to initaliases in diraliases.c.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/pure-ftpdto a version that resolves this vulnerability.Fixed in 1.0.49-4.1Fixed in 1.0.49-4.1+deb11u1Fixed in 1.0.50-2.1Fixed in 1.0.50-2.2 - Upgrade
Upgrade
Pure-FTPdto a version that resolves this vulnerability.Fixed in 1.0.49
Event History
Frequently Asked Questions
What is CVE-2020-9274?
CVE-2020-9274 is a vulnerability found in Pure-FTPd 1.0.49 that allows for an uninitialized pointer exploit.
What is the severity of CVE-2020-9274?
The severity of CVE-2020-9274 is high with a CVSS score of 7.5.
Which software versions are affected by CVE-2020-9274?
The affected software versions include Pure-FTPd 1.0.49-4.1, 1.0.50-2.1, 1.0.49-4, and 1.0.36-3.2+.
How can I fix CVE-2020-9274?
To fix CVE-2020-9274, update to a patched version of Pure-FTPd, such as 1.0.49-4.1 or 1.0.50-2.1.
Where can I find more information about CVE-2020-9274?
More information about CVE-2020-9274 can be found on the following references: [link1], [link2], [link3]