It has been discovered that lftp up to and including version 4.8.3 does not properly sanitize remote file names, leading to a loss of integrity on the local system when reverse mirroring is used. A remote attacker may trick a user to use reverse mirroring on an attacker controlled FTP server, resulting in the removal of all files in the current working directory of the victim's system.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2018-08-01T14:00:00

Updated: 2024-08-05T07:54:35.215Z

Reserved: 2018-05-09T00:00:00

Link: CVE-2018-10916

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-08-01T14:29:00.440

Modified: 2019-04-02T18:29:01.457

Link: CVE-2018-10916

cve-icon Redhat

Severity : Moderate

Publid Date: 2018-05-16T00:00:00Z

Links: CVE-2018-10916 - Bugzilla