See how pure-ftpd compares to other vendors in security performance
pure-ftpd before 1.0.52 is vulnerable to Buffer Overflow. There is an out of bounds read in the domlsd() function of the ls.c file.
Multiple libc/glob(3) flaws were reported [1] that affect various BSD libc implementations. In particular, globs containing braces could lead to resource exhaustion.
One such vulnerable application is Pure-FTPd. This has been corrected in upstream version 1.0.32, where support for braces expansion in directory listings was disabled.
[1] http://securityreason.com/achievementsecurityalert/97 [2] http://www.pureftpd.org/project/pure-ftpd/news