CVE-2021-40524: Malicious File Upload
In Pure-FTPd before 1.0.50, an incorrect maxfilesize quota mechanism in the server allows attackers to upload files of unbounded size, which may lead to denial of service or a server hang. This occurs because a certain greater-than-zero test does not anticipate an initial -1 value. (Versions 1.0.23 through 1.0.49 are affected.)
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Pure-FTPdto a version that resolves this vulnerability.Fixed in 1.0.50
Event History
Frequently Asked Questions
What is the CVE ID for this vulnerability?
The CVE ID for this vulnerability is CVE-2021-40524.
What is the severity level of CVE-2021-40524?
The severity level of CVE-2021-40524 is high.
How does CVE-2021-40524 affect Pure-FTPd?
CVE-2021-40524 affects Pure-FTPd versions before 1.0.50.
What is the potential impact of CVE-2021-40524?
The potential impact of CVE-2021-40524 is denial of service or server hang.
Is there a fix available for CVE-2021-40524?
Yes, a fix is available for CVE-2021-40524. Upgrade to Pure-FTPd version 1.0.50 or later.