Pure-FTPd versions ≤ 1.0.49 (>= ~0.96) contain a vulnerability in the init_aliases() function within diraliases.c when processing aliases. This leads to access of an uninitialized pointer, which can cause a denial of service (DoS) condition.
id: CVE-2020-9274
info:
name: Pure-FTPd ≤ 1.0.49 - DoS via Uninitialized Pointer
author: pussyc
...