445
VMScore

CVE-2021-40524

Published: 05/09/2021 Updated: 26/11/2021
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

In Pure-FTPd prior to 1.0.50, an incorrect max_filesize quota mechanism in the server allows malicious users to upload files of unbounded size, which may lead to denial of service or a server hang. This occurs because a certain greater-than-zero test does not anticipate an initial -1 value. (Versions 1.0.23 up to and including 1.0.49 are affected.)

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

pureftpd pure-ftpd

Vendor Advisories

Debian Bug report logs - #993810 pure-ftpd: CVE-2021-40524 Package: src:pure-ftpd; Maintainer for src:pure-ftpd is Stefan Hornburg (Racke) <racke@linuxiade>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 6 Sep 2021 19:06:02 UTC Severity: important Tags: security, upstream Found in version pure-f ...