VYPR
High severity7.5NVD Advisory· Published Feb 26, 2020· Updated Jun 17, 2026

CVE-2020-9274

CVE-2020-9274

Description

An issue was discovered in Pure-FTPd 1.0.49. An uninitialized pointer vulnerability has been detected in the diraliases linked list. When the *lookup_alias(const char alias) or print_aliases(void) function is called, they fail to correctly detect the end of the linked list and try to access a non-existent list member. This is related to init_aliases in diraliases.c.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

11
  • cpe:2.3:a:fedoraproject:extra_packages_for_enterprise_linux:7.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:fedoraproject:extra_packages_for_enterprise_linux:7.0:*:*:*:*:*:*:*
    • cpe:2.3:a:fedoraproject:extra_packages_for_enterprise_linux:8.0:*:*:*:*:*:*:*
  • Pureftpd/Pureftpd2 versions
    cpe:2.3:a:pureftpd:pure-ftpd:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:pureftpd:pure-ftpd:*:*:*:*:*:*:*:*range: <1.0.50
    • (no CPE)range: <=1.0.49
  • cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*
  • cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
  • cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*
    • cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*
    • cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*
  • Pure-FTPd/Pure-FTPddescription

Patches

Vulnerability mechanics

References

8

News mentions

0

No linked articles in our index yet.