Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-10916

Опубликовано: 16 мая 2018
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

It has been discovered that lftp up to and including version 4.8.3 does not properly sanitize remote file names, leading to a loss of integrity on the local system when reverse mirroring is used. A remote attacker may trick a user to use reverse mirroring on an attacker controlled FTP server, resulting in the removal of all files in the current working directory of the victim's system.

It has been discovered that lftp does not properly sanitize remote file names, leading to a loss of integrity on the local system when reverse mirroring is used. A remote attacker may trick a user to use reverse mirroring on an attacker-controlled FTP server, resulting in the removal of all files in the current working directory of the victim's system.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5lftpNot affected
Red Hat Enterprise Linux 6lftpWill not fix
Red Hat Enterprise Linux 8lftpNot affected
Red Hat Enterprise Linux 7lftpFixedRHSA-2020:104531.03.2020

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1610349lftp: particular remote file names may lead to current working directory erased

EPSS

Процентиль: 91%
0.04782
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 8 лет назад

It has been discovered that lftp up to and including version 4.8.3 does not properly sanitize remote file names, leading to a loss of integrity on the local system when reverse mirroring is used. A remote attacker may trick a user to use reverse mirroring on an attacker controlled FTP server, resulting in the removal of all files in the current working directory of the victim's system.

CVSS3: 5.3
nvd
около 8 лет назад

It has been discovered that lftp up to and including version 4.8.3 does not properly sanitize remote file names, leading to a loss of integrity on the local system when reverse mirroring is used. A remote attacker may trick a user to use reverse mirroring on an attacker controlled FTP server, resulting in the removal of all files in the current working directory of the victim's system.

CVSS3: 5.3
debian
около 8 лет назад

It has been discovered that lftp up to and including version 4.8.3 doe ...

suse-cvrf
больше 7 лет назад

Security update for lftp

suse-cvrf
больше 7 лет назад

Security update for lftp

EPSS

Процентиль: 91%
0.04782
Низкий

5.3 Medium

CVSS3