NULL pointer dereference in uftpd - CVE-2020-14149
Published: July 2, 2020
uftpd
Joachim Nilsson
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error in uftpd within the handle_CWD in ftpcmd.c when processing the CWD /. command. A remote authenticated user can send a specially crafted command to the server and perform a denial of service (DoS) attack.