Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2018-10916

Опубликовано: 01 авг. 2018
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 7.8
CVSS3: 5.3

Описание

It has been discovered that lftp up to and including version 4.8.3 does not properly sanitize remote file names, leading to a loss of integrity on the local system when reverse mirroring is used. A remote attacker may trick a user to use reverse mirroring on an attacker controlled FTP server, resulting in the removal of all files in the current working directory of the victim's system.

РелизСтатусПримечание
bionic

released

4.8.1-1ubuntu0.1
devel

not-affected

4.8.4-1
esm-infra-legacy/trusty

released

4.4.13-1ubuntu0.1
esm-infra/bionic

released

4.8.1-1ubuntu0.1
esm-infra/xenial

released

4.6.3a-1ubuntu0.1
precise/esm

not-affected

4.3.3-1ubuntu0.1
trusty

released

4.4.13-1ubuntu0.1
trusty/esm

released

4.4.13-1ubuntu0.1
upstream

released

4.8.4-1
xenial

released

4.6.3a-1ubuntu0.1

Показывать по

EPSS

Процентиль: 71%
0.00696
Низкий

7.8 High

CVSS2

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
redhat
больше 7 лет назад

It has been discovered that lftp up to and including version 4.8.3 does not properly sanitize remote file names, leading to a loss of integrity on the local system when reverse mirroring is used. A remote attacker may trick a user to use reverse mirroring on an attacker controlled FTP server, resulting in the removal of all files in the current working directory of the victim's system.

CVSS3: 5.3
nvd
больше 7 лет назад

It has been discovered that lftp up to and including version 4.8.3 does not properly sanitize remote file names, leading to a loss of integrity on the local system when reverse mirroring is used. A remote attacker may trick a user to use reverse mirroring on an attacker controlled FTP server, resulting in the removal of all files in the current working directory of the victim's system.

CVSS3: 5.3
debian
больше 7 лет назад

It has been discovered that lftp up to and including version 4.8.3 doe ...

suse-cvrf
почти 7 лет назад

Security update for lftp

suse-cvrf
почти 7 лет назад

Security update for lftp

EPSS

Процентиль: 71%
0.00696
Низкий

7.8 High

CVSS2

5.3 Medium

CVSS3