VYPR
Critical severity9.8NVD Advisory· Published May 12, 2020· Updated Jun 17, 2026

CVE-2020-1939

CVE-2020-1939

Description

The Apache NuttX (Incubating) project provides an optional separate "apps" repository which contains various optional components and example programs. One of these, ftpd, had a NULL pointer dereference bug. The NuttX RTOS itself is not affected. Users of the optional apps repository are affected only if they have enabled ftpd. Versions 6.15 to 8.2 are affected.

Affected products

3
  • cpe:2.3:a:apache:nuttx:*:*:*:*:*:*:*:*
    Range: >=6.15,<=8.2
  • Apache/NuttX (Incubating) apps repositorydescription
  • Apache/ftpdllm-create
    Range: 6.15 to 8.2

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.