Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-10916

Опубликовано: 01 авг. 2018
Источник: debian

Описание

It has been discovered that lftp up to and including version 4.8.3 does not properly sanitize remote file names, leading to a loss of integrity on the local system when reverse mirroring is used. A remote attacker may trick a user to use reverse mirroring on an attacker controlled FTP server, resulting in the removal of all files in the current working directory of the victim's system.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
lftpfixed4.8.4-1package
lftpno-dsastretchpackage
lftpno-dsajessiepackage

Примечания

  • https://github.com/lavv17/lftp/issues/452

  • https://github.com/lavv17/lftp/commit/a27e07d90a4608ceaf928b1babb27d4d803e1992

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 8 лет назад

It has been discovered that lftp up to and including version 4.8.3 does not properly sanitize remote file names, leading to a loss of integrity on the local system when reverse mirroring is used. A remote attacker may trick a user to use reverse mirroring on an attacker controlled FTP server, resulting in the removal of all files in the current working directory of the victim's system.

CVSS3: 5.3
redhat
около 8 лет назад

It has been discovered that lftp up to and including version 4.8.3 does not properly sanitize remote file names, leading to a loss of integrity on the local system when reverse mirroring is used. A remote attacker may trick a user to use reverse mirroring on an attacker controlled FTP server, resulting in the removal of all files in the current working directory of the victim's system.

CVSS3: 5.3
nvd
около 8 лет назад

It has been discovered that lftp up to and including version 4.8.3 does not properly sanitize remote file names, leading to a loss of integrity on the local system when reverse mirroring is used. A remote attacker may trick a user to use reverse mirroring on an attacker controlled FTP server, resulting in the removal of all files in the current working directory of the victim's system.

suse-cvrf
больше 7 лет назад

Security update for lftp

suse-cvrf
больше 7 лет назад

Security update for lftp