{"id":"openSUSE-SU-2020:0865-1","summary":"Security update for uftpd","details":"This update for uftpd fixes the following issues:\n\nuftpd was updated to version 2.12.\n\nChanges:\n\n* Use common log message format and log level when user enters\n  an invalid path. This unfortunately affects changes introduced\n  in v2.11 to increase logging at default log level.\n\nSecurity fixes:\n\n- CVE-2020-14149: When entering an invalid directory with the FTP\n  command CWD, a NULL ptr was deref. in a DBG() message even\n  though the log level is set to a value lower than LOG_DEBUG.\n  This caused uftpd to crash and cause denial of service.\n  Depending on the init/inetd system used this could be\n  permanent. (boo#1172959)\n","modified":"2025-05-07T18:11:30.486330Z","published":"2020-06-25T12:18:25Z","related":["CVE-2020-14149"],"upstream":["CVE-2020-14149"],"references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/7ZZVJKHMYEKLIWMJZN53DLSBGWMF5BNS/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1172959"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-14149"}],"affected":[{"package":{"name":"uftpd","ecosystem":"openSUSE:Leap 15.1","purl":"pkg:rpm/opensuse/uftpd&distro=openSUSE%20Leap%2015.1"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.12-lp151.2.6.1"}]}],"ecosystem_specific":{"binaries":[{"uftpd":"2.12-lp151.2.6.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2020:0865-1.json"}}],"schema_version":"1.7.3"}