Vulnerability Name: | CVE-2017-12170 (CCN-132520) | ||||||||||||||||
Assigned: | 2017-08-01 | ||||||||||||||||
Published: | 2017-08-01 | ||||||||||||||||
Updated: | 2019-10-03 | ||||||||||||||||
Summary: | Downstream version 1.0.46-1 of pure-ftpd as shipped in Fedora was vulnerable to packaging error due to which the original configuration was ignored after update and service started running with default configuration. This has security implications because of overriding security-related configuration. This issue doesn't affect upstream version of pure-ftpd. | ||||||||||||||||
CVSS v3 Severity: | 9.8 Critical (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) 8.6 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:U/RC:R)
4.7 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:U/RL:U/RC:R)
| ||||||||||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||||||||||
Vulnerability Type: | CWE-noinfo | ||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2017-12170 Source: CCN Type: Red Hat Bugzilla Bug 1493114 (CVE-2017-12170) CVE-2017-12170 pure-ftpd: Ignoring existing configuration after update due to packaging error Source: CONFIRM Type: Issue Tracking, Tool Signature, VDB Entry https://bugzilla.redhat.com/show_bug.cgi?id=1493114 Source: XF Type: UNKNOWN pureftpd-cve201712170-unspecified(132520) Source: CCN Type: Pure-FTPd Web site Pure-FTPd | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: ![]() | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |