Oval Definition:oval:org.opensuse.security:def:202140524
Revision Date:2022-06-30Version:1
Title:CVE-2021-40524
Description:

In Pure-FTPd before 1.0.50, an incorrect max_filesize quota mechanism in the server allows attackers to upload files of unbounded size, which may lead to denial of service or a server hang. This occurs because a certain greater-than-zero test does not anticipate an initial -1 value. (Versions 1.0.23 through 1.0.49 are affected.)
Family:unixClass:vulnerability
Status:Reference(s):Mitre CVE-2021-40524
SUSE CVE-2021-40524
Platform(s):openSUSE Tumbleweed
SUSE Linux Enterprise Server 11 SP1
SUSE Linux Enterprise Server 11 SP3
Product(s):
Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Server 11 SP1 is installed
  • OR SUSE Linux Enterprise Server 11 SP3 is installed
  • AND pure-ftpd is affected
  • Definition Synopsis
  • openSUSE Tumbleweed is installed
  • AND pure-ftpd-1.0.50-1.1 is installed
  • BACK