Vulnerability Details CVE-2021-40524
In Pure-FTPd before 1.0.50, an incorrect max_filesize quota mechanism in the server allows attackers to upload files of unbounded size, which may lead to denial of service or a server hang. This occurs because a certain greater-than-zero test does not anticipate an initial -1 value. (Versions 1.0.23 through 1.0.49 are affected.)
Exploit prediction scoring system (EPSS) score
EPSS Score 0.006
EPSS Ranking 67.7%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2021-40524
-
cpe:2.3:a:pureftpd:pure-ftpd:1.0.23
-
cpe:2.3:a:pureftpd:pure-ftpd:1.0.24
-
cpe:2.3:a:pureftpd:pure-ftpd:1.0.25
-
cpe:2.3:a:pureftpd:pure-ftpd:1.0.26
-
cpe:2.3:a:pureftpd:pure-ftpd:1.0.27
-
cpe:2.3:a:pureftpd:pure-ftpd:1.0.28
-
cpe:2.3:a:pureftpd:pure-ftpd:1.0.29
-
cpe:2.3:a:pureftpd:pure-ftpd:1.0.30
-
cpe:2.3:a:pureftpd:pure-ftpd:1.0.31
-
cpe:2.3:a:pureftpd:pure-ftpd:1.0.32
-
cpe:2.3:a:pureftpd:pure-ftpd:1.0.34
-
cpe:2.3:a:pureftpd:pure-ftpd:1.0.35
-
cpe:2.3:a:pureftpd:pure-ftpd:1.0.36
-
cpe:2.3:a:pureftpd:pure-ftpd:1.0.37
-
cpe:2.3:a:pureftpd:pure-ftpd:1.0.38
-
cpe:2.3:a:pureftpd:pure-ftpd:1.0.39
-
cpe:2.3:a:pureftpd:pure-ftpd:1.0.40
-
cpe:2.3:a:pureftpd:pure-ftpd:1.0.41
-
cpe:2.3:a:pureftpd:pure-ftpd:1.0.42
-
cpe:2.3:a:pureftpd:pure-ftpd:1.0.43
-
cpe:2.3:a:pureftpd:pure-ftpd:1.0.44
-
cpe:2.3:a:pureftpd:pure-ftpd:1.0.45
-
cpe:2.3:a:pureftpd:pure-ftpd:1.0.46
-
cpe:2.3:a:pureftpd:pure-ftpd:1.0.46-1
-
cpe:2.3:a:pureftpd:pure-ftpd:1.0.47
-
cpe:2.3:a:pureftpd:pure-ftpd:1.0.48
-
cpe:2.3:a:pureftpd:pure-ftpd:1.0.49