PT-2020-18972 · Bftpd · Bftpd

Published

2020-01-10

·

Updated

2020-01-23

·

CVE-2020-6162

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Bftpd version 5.3
Description An issue was discovered that triggers an out-of-bounds read due to an uninitialized value. This causes the daemon to crash at startup in the hidegroups init function in dirlist.c.
Recommendations For Bftpd version 5.3, consider disabling the hidegroups init function as a temporary workaround until a patch is available. At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-6162

Affected Products

Bftpd