pure-ftpd before 1.0.52 is vulnerable to Buffer Overflow. There is an out of bounds read in the domlsd() function of the ls.c file.
{
"binaries": [
{
"binary_name": "pure-ftpd",
"binary_version": "1.0.36-3.2+deb8u1build0.16.04.1"
},
{
"binary_name": "pure-ftpd-common",
"binary_version": "1.0.36-3.2+deb8u1build0.16.04.1"
},
{
"binary_name": "pure-ftpd-ldap",
"binary_version": "1.0.36-3.2+deb8u1build0.16.04.1"
},
{
"binary_name": "pure-ftpd-mysql",
"binary_version": "1.0.36-3.2+deb8u1build0.16.04.1"
},
{
"binary_name": "pure-ftpd-postgresql",
"binary_version": "1.0.36-3.2+deb8u1build0.16.04.1"
}
]
}{
"binaries": [
{
"binary_name": "pure-ftpd",
"binary_version": "1.0.46-1ubuntu18.04.1"
},
{
"binary_name": "pure-ftpd-common",
"binary_version": "1.0.46-1ubuntu18.04.1"
},
{
"binary_name": "pure-ftpd-ldap",
"binary_version": "1.0.46-1ubuntu18.04.1"
},
{
"binary_name": "pure-ftpd-mysql",
"binary_version": "1.0.46-1ubuntu18.04.1"
},
{
"binary_name": "pure-ftpd-postgresql",
"binary_version": "1.0.46-1ubuntu18.04.1"
}
]
}{
"binaries": [
{
"binary_name": "pure-ftpd",
"binary_version": "1.0.49-4ubuntu0.1"
},
{
"binary_name": "pure-ftpd-common",
"binary_version": "1.0.49-4ubuntu0.1"
},
{
"binary_name": "pure-ftpd-ldap",
"binary_version": "1.0.49-4ubuntu0.1"
},
{
"binary_name": "pure-ftpd-mysql",
"binary_version": "1.0.49-4ubuntu0.1"
},
{
"binary_name": "pure-ftpd-postgresql",
"binary_version": "1.0.49-4ubuntu0.1"
}
]
}{
"binaries": [
{
"binary_name": "pure-ftpd",
"binary_version": "1.0.50-2.1ubuntu0.22.04.1"
},
{
"binary_name": "pure-ftpd-common",
"binary_version": "1.0.50-2.1ubuntu0.22.04.1"
},
{
"binary_name": "pure-ftpd-ldap",
"binary_version": "1.0.50-2.1ubuntu0.22.04.1"
},
{
"binary_name": "pure-ftpd-mysql",
"binary_version": "1.0.50-2.1ubuntu0.22.04.1"
},
{
"binary_name": "pure-ftpd-postgresql",
"binary_version": "1.0.50-2.1ubuntu0.22.04.1"
}
]
}{
"binaries": [
{
"binary_name": "pure-ftpd",
"binary_version": "1.0.50-2.2build2"
},
{
"binary_name": "pure-ftpd-common",
"binary_version": "1.0.50-2.2build2"
},
{
"binary_name": "pure-ftpd-ldap",
"binary_version": "1.0.50-2.2build2"
},
{
"binary_name": "pure-ftpd-mysql",
"binary_version": "1.0.50-2.2build2"
},
{
"binary_name": "pure-ftpd-postgresql",
"binary_version": "1.0.50-2.2build2"
}
]
}{
"binaries": [
{
"binary_name": "pure-ftpd",
"binary_version": "1.0.50-2.2build3"
},
{
"binary_name": "pure-ftpd-common",
"binary_version": "1.0.50-2.2build3"
},
{
"binary_name": "pure-ftpd-ldap",
"binary_version": "1.0.50-2.2build3"
},
{
"binary_name": "pure-ftpd-mysql",
"binary_version": "1.0.50-2.2build3"
},
{
"binary_name": "pure-ftpd-postgresql",
"binary_version": "1.0.50-2.2build3"
}
]
}{
"binaries": [
{
"binary_name": "pure-ftpd",
"binary_version": "1.0.50-2.2build3"
},
{
"binary_name": "pure-ftpd-common",
"binary_version": "1.0.50-2.2build3"
},
{
"binary_name": "pure-ftpd-ldap",
"binary_version": "1.0.50-2.2build3"
},
{
"binary_name": "pure-ftpd-mysql",
"binary_version": "1.0.50-2.2build3"
},
{
"binary_name": "pure-ftpd-postgresql",
"binary_version": "1.0.50-2.2build3"
}
]
}