Analyst readout for executives and security teams
Plain-English summary
Pure-FTPd 1.0.49 has a stack exhaustion flaw in its directory listing code. For an organization, the main concern is FTP service disruption if vulnerable servers are reachable. The source bundle does not provide CVSS, CWE, or confirmed active exploitation evidence.
Executive priority
Treat this as a moderate availability risk for any exposed FTP service. Prioritize internet-facing Pure-FTPd systems first, especially where FTP availability supports customer, partner, or operational workflows.
Technical view
CVE-2019-20176 describes stack exhaustion in Pure-FTPd 1.0.49 within listdir in ls.c. Upstream has a referenced commit, and Fedora issued package advisories. Available evidence points to an availability issue; the bundle does not establish code execution, affected downstream versions, or exploitation in the wild.
Likely exposure
Exposure is most likely where Pure-FTPd 1.0.49, or distro packages based on it, provide FTP service. Internet-facing FTP services carry higher operational risk. The bundle does not identify CPEs or a full affected version range.
Exploitation context
CISA KEV status is false, and the supplied sources do not cite active exploitation. The known issue is tied to directory listing logic, but the bundle does not provide exploit prerequisites or reliable attack complexity details.
Researcher notes
The record is sparse: no CVSS vector, CWE, CPE, or exploit status is supplied. Analysis should stay anchored to Pure-FTPd 1.0.49, listdir in ls.c, the upstream commit, and Fedora advisories until vendor-specific evidence expands scope.
Mitigation direction
- Identify Pure-FTPd deployments and confirm installed package versions.
- Apply Fedora vendor updates where using affected Fedora packages.
- For source builds, verify inclusion of the referenced upstream commit.
- Restrict FTP exposure to trusted networks where business allows.
- Monitor vendor advisories for confirmed fixed versions and downstream backports.
Validation and detection
- Inventory hosts exposing FTP and map them to Pure-FTPd versions.
- Check package changelogs for CVE-2019-20176 or the upstream commit.
- Confirm patched services are restarted after updates.
- Review service logs for abnormal directory listing failures or crashes.
- Validate external exposure with approved asset management tooling.
Public sources used
Based on public source material and reviewed before publication.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2019-20176 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- https://github.com/jedisct1/pure-ftpd/commit/aea56f4bcb9948d456f3fae4d044fd3fa2e19706CVE reference · x_refsource_MISC
- FEDORA-2020-74b71e5873CVE reference · vendor-advisory, x_refsource_FEDORA
- FEDORA-2020-85fa9f07f4CVE reference · vendor-advisory, x_refsource_FEDORA
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
