Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2020-1045

Опубликовано: 06 апр. 2020
Источник: oracle-oval
Платформа: Oracle Linux 7

Описание

ELSA-2020-1045: lftp security update (MODERATE)

[4.4.8-12]

  • Resolves: #1611641 - CVE-2018-10916 lftp: particular remote file names may lead to current working directory erased

Обновленные пакеты

Oracle Linux 7

Oracle Linux aarch64

lftp

4.4.8-12.el7

lftp-scripts

4.4.8-12.el7

Oracle Linux x86_64

lftp

4.4.8-12.el7

lftp-scripts

4.4.8-12.el7

Связанные CVE

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 7 лет назад

It has been discovered that lftp up to and including version 4.8.3 does not properly sanitize remote file names, leading to a loss of integrity on the local system when reverse mirroring is used. A remote attacker may trick a user to use reverse mirroring on an attacker controlled FTP server, resulting in the removal of all files in the current working directory of the victim's system.

CVSS3: 5.3
redhat
больше 7 лет назад

It has been discovered that lftp up to and including version 4.8.3 does not properly sanitize remote file names, leading to a loss of integrity on the local system when reverse mirroring is used. A remote attacker may trick a user to use reverse mirroring on an attacker controlled FTP server, resulting in the removal of all files in the current working directory of the victim's system.

CVSS3: 5.3
nvd
больше 7 лет назад

It has been discovered that lftp up to and including version 4.8.3 does not properly sanitize remote file names, leading to a loss of integrity on the local system when reverse mirroring is used. A remote attacker may trick a user to use reverse mirroring on an attacker controlled FTP server, resulting in the removal of all files in the current working directory of the victim's system.

CVSS3: 5.3
debian
больше 7 лет назад

It has been discovered that lftp up to and including version 4.8.3 doe ...

suse-cvrf
почти 7 лет назад

Security update for lftp