There are multiple unauthenticated directory traversal vulnerabilities in different FTP commands in uftpd FTP server versions 2.7 to 2.10 due to improper implementation of a chroot jail in common.c's compose_abspath function that can be abused to read or write to arbitrary files on the filesystem, leak process memory, or potentially lead to remote code execution.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-20277.json"
[
{
"digest": {
"line_hashes": [
"108229206972147259569248804372767412868",
"276360762841382069748424337075868013451",
"242312807191981524080516238265272007214",
"250357959569044888915036652998736230067"
],
"threshold": 0.9
},
"id": "CVE-2020-20277-6bb940c7",
"signature_type": "Line",
"source": "https://github.com/troglobit/uftpd/commit/455b47d3756aed162d2d0ef7f40b549f3b5b30fe",
"target": {
"file": "src/common.c"
},
"deprecated": false,
"signature_version": "v1"
}
]