Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2019:1059-1

Опубликовано: 27 мар. 2019
Источник: suse-cvrf

Описание

Security update for lftp

This update for lftp fixes the following issues:

Security issue fixed:

  • CVE-2018-10916: Fixed an improper file name sanitization which could lead to loss of integrity of the local system (bsc#1103367).

Other issue addressed:

  • The SSH login handling code detects password prompts more reliably (bsc#1120946).

This update was imported from the SUSE:SLE-12-SP3:Update update project.

Список пакетов

openSUSE Leap 42.3
lftp-4.7.4-2.6.1

Описание

It has been discovered that lftp up to and including version 4.8.3 does not properly sanitize remote file names, leading to a loss of integrity on the local system when reverse mirroring is used. A remote attacker may trick a user to use reverse mirroring on an attacker controlled FTP server, resulting in the removal of all files in the current working directory of the victim's system.


Затронутые продукты
openSUSE Leap 42.3:lftp-4.7.4-2.6.1

Ссылки