Vulnerability Intelligence Report
CVE-2020-9274
An issue was discovered in Pure-FTPd 1.0.49. An uninitialized pointer vulnerability has been detected in the diraliases linked list. When the *lookup_alias(const char alias) or print_aliases(void) function is called, they fail to correctly detect the end of the linked list and try to access a non-existent list member. This is related to init_aliases in diraliases.c.
Nuclei Template
CVSS Base Score
7.5
HIGH
EPSS Probability:5.81%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| pureftpd | pure-ftpd | all |
| debian | debian_linux | 8.0 |
| fedoraproject | extra_packages_for_enterprise_linux | 7.0, 8.0 |
| fedoraproject | fedora | 30, 31, 32 |
| canonical | ubuntu_linux | 16.04 |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | MITRE Corporation · N/A · USA |
| Reserved | 2020-02-19T00:00:00 |
| Published | 2020-02-26T15:29:32 |
| Last Updated | 2024-08-04T10:26:16 |
Community Chatter & Buzz