Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-10916

Опубликовано: 01 авг. 2018
Источник: debian
EPSS Низкий

Описание

It has been discovered that lftp up to and including version 4.8.3 does not properly sanitize remote file names, leading to a loss of integrity on the local system when reverse mirroring is used. A remote attacker may trick a user to use reverse mirroring on an attacker controlled FTP server, resulting in the removal of all files in the current working directory of the victim's system.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
lftpfixed4.8.4-1package
lftpno-dsastretchpackage
lftpno-dsajessiepackage

Примечания

  • https://github.com/lavv17/lftp/issues/452

  • https://github.com/lavv17/lftp/commit/a27e07d90a4608ceaf928b1babb27d4d803e1992

EPSS

Процентиль: 71%
0.00696
Низкий

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 7 лет назад

It has been discovered that lftp up to and including version 4.8.3 does not properly sanitize remote file names, leading to a loss of integrity on the local system when reverse mirroring is used. A remote attacker may trick a user to use reverse mirroring on an attacker controlled FTP server, resulting in the removal of all files in the current working directory of the victim's system.

CVSS3: 5.3
redhat
больше 7 лет назад

It has been discovered that lftp up to and including version 4.8.3 does not properly sanitize remote file names, leading to a loss of integrity on the local system when reverse mirroring is used. A remote attacker may trick a user to use reverse mirroring on an attacker controlled FTP server, resulting in the removal of all files in the current working directory of the victim's system.

CVSS3: 5.3
nvd
больше 7 лет назад

It has been discovered that lftp up to and including version 4.8.3 does not properly sanitize remote file names, leading to a loss of integrity on the local system when reverse mirroring is used. A remote attacker may trick a user to use reverse mirroring on an attacker controlled FTP server, resulting in the removal of all files in the current working directory of the victim's system.

suse-cvrf
почти 7 лет назад

Security update for lftp

suse-cvrf
почти 7 лет назад

Security update for lftp

EPSS

Процентиль: 71%
0.00696
Низкий