ftpserver.py in pyftpdlib before 0.5.2 does not require the l permission for the MLST command, which allows remote authenticated users to bypass intended access restrictions and list the root directory via an FTP session.
Advisories
Source ID Title
EUVD EUVD EUVD-2010-0027 ftpserver.py in pyftpdlib before 0.5.2 does not require the l permission for the MLST command, which allows remote authenticated users to bypass intended access restrictions and list the root directory via an FTP session.
Github GHSA Github GHSA GHSA-h4g7-8m7r-87r9 Improper Access Control in pyftpdlib
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-09-17T01:55:56.448Z

Reserved: 2010-10-19T00:00:00Z

Link: CVE-2009-5012

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2010-10-19T20:00:03.050

Modified: 2025-04-11T00:51:21.963

Link: CVE-2009-5012

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.