debian · CVE-2017-12170

Quick triage

Priority: unimportant Published: Updated: Sat, 06 Jun 2026 14:37:25 GMT

View at Official debian advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2017-12170 unimportant priority: Debian including 1 source packages (pure-ftpd), 4 status rows across 4 suites (bookworm, bullseye, sid, trixie): resolved 4.

Description:

Downstream version 1.0.46-1 of pure-ftpd as shipped in Fedora was vulnerable to packaging error due to which the original configuration was ignored after update and service started running with default configuration. This has security implications because of overriding security-related configuration. This issue doesn't affect upstream version of pure-ftpd.

cvelogic Threat Intelligence