First published: Mon Feb 24 2020(Updated: )
An issue was discovered in Pure-FTPd 1.0.49. An out-of-bounds (OOB) read has been detected in the pure_strcmp function in utils.c.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Pureftpd Pure-ftpd | =1.0.49 | |
Fedoraproject Fedora | =30 | |
Fedoraproject Fedora | =31 | |
Fedoraproject Fedora | =32 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-9365 is high with a CVSS score of 7.5.
The affected software for CVE-2020-9365 is Pure-FTPd 1.0.49, Fedora 30, Fedora 31, and Fedora 32.
CVE-2020-9365 is an out-of-bounds (OOB) read vulnerability in the pure_strcmp function in utils.c of Pure-FTPd 1.0.49.
To fix CVE-2020-9365, it is recommended to update to a patched version of Pure-FTPd (1.0.50 or later) or apply any available security patches provided by the vendor.
More information about CVE-2020-9365 can be found on the GitHub commits (36c6d268cb190282a2c17106acfd31863121b58e, bf6fcd4935e95128cf22af5924cdc8fe5c0579da) and the Fedora Project mailing list announcement.