Vulnerability Intelligence Report
CVE-2017-12170
Downstream version 1.0.46-1 of pure-ftpd as shipped in Fedora was vulnerable to packaging error due to which the original configuration was ignored after update and service started running with default configuration. This has security implications because of overriding security-related configuration. This issue doesn't affect upstream version of pure-ftpd.
No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
EPSS Probability:1.52%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Red Hat, Inc. | pure-ftpd | Fedora downstream version pure-ftpd-1.0.46-1 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
1.517%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Red Hat, Inc. · Vendor · USA |
| Reserved | 2017-08-01T00:00:00 |
| Published | 2017-09-21T20:00:00 |
| Patch Date | 2017-08-14 |
| Last Updated | 2024-08-05T18:28:16 |
Community Chatter & Buzz