An issue was discovered in Pure-FTPd 1.0.49. An out-of-bounds (OOB) read has been detected in the pure_strcmp function in utils.c.
{
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "30"
},
{
"last_affected": "30"
},
{
"introduced": "31"
},
{
"last_affected": "31"
},
{
"introduced": "32"
},
{
"last_affected": "32"
}
],
"source": "CPE_STRING",
"vendor_product": "fedoraproject:fedora",
"cpes": [
"cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*",
"cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*",
"cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*"
]
}
]
}{
"extracted_events": [
{
"introduced": "1.0.49"
},
{
"last_affected": "1.0.49"
}
],
"source": [
"CPE_STRING",
"REFERENCES"
],
"cpe": "cpe:2.3:a:pureftpd:pure-ftpd:1.0.49:*:*:*:*:*:*:*"
}
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-9365.json"
[
{
"target": {
"file": "src/utils.c"
},
"deprecated": false,
"source": "https://github.com/jedisct1/pure-ftpd/commit/bf6fcd4935e95128cf22af5924cdc8fe5c0579da",
"id": "CVE-2020-9365-7e5360e1",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"95891114108689080271635707879851571584",
"336842005398644163625468051387470758073"
]
},
"signature_type": "Line"
},
{
"target": {
"file": "src/utils.c"
},
"deprecated": false,
"source": "https://github.com/jedisct1/pure-ftpd/commit/36c6d268cb190282a2c17106acfd31863121b58e",
"id": "CVE-2020-9365-85e7bab8",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"95891114108689080271635707879851571584",
"336842005398644163625468051387470758073"
]
},
"signature_type": "Line"
}
]
"2026-07-09T00:12:17Z"