CVE-2017-12170: Fedoraproject Fedora
Critical severity, CVSS 9.8. EPSS: 1.5% chance of exploitation in the next 30 days.
Downstream version 1.0.46-1 of pure-ftpd as shipped in Fedora was vulnerable to packaging error due to which the original configuration was ignored after update and service started running with default configuration. This has security implications because of overriding security-related configuration. This issue doesn't affect upstream version of pure-ftpd.
Affected products
- Fedoraproject Fedora: version 26 only; version 27 only
- Pureftpd Pure-Ftpd: version 1.0.46-1 only
Published 2017-09-21. Last modified 2026-06-17.