Pure Ftpd · Pure-Ftpd · CVE-2021-40524
**Name of the Vulnerable Software and Affected Versions**
Pure-FTPd versions 1.0.23 through 1.0.49
**Description**
The issue arises from an incorrect max filesize quota mechanism in the server, allowing attackers to upload files of unbounded size. This can lead to denial of service or a server hang due to a certain greater-than-zero test not anticipating an initial -1 value.
**Recommendations**
For versions 1.0.23 through 1.0.49, update to version 1.0.50 or later to resolve the issue.