Description
Downstream version 1.0.46-1 of pure-ftpd as shipped in Fedora was vulnerable to packaging error due to which the original configuration was ignored after update and service started running with default configuration. This has security implications because of overriding security-related configuration. This issue doesn't affect upstream version of pure-ftpd.
References (1)
Core 1
Core References
Issue Tracking, Tool Signature, VDB Entry x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=1493114
Scores
CVSS v3
9.8
EPSS
0.0152
EPSS Percentile
71.9%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
Status
published
Products (4)
fedoraproject/fedora
26
fedoraproject/fedora
27
pureftpd/pure-ftpd
1.0.46-1
Red Hat, Inc./pure-ftpd
Fedora downstream version pure-ftpd-1.0.46-1
Published
Sep 21, 2017
Tracked Since
Feb 18, 2026