Description
It has been discovered that lftp up to and including version 4.8.3 does not properly sanitize remote file names, leading to a loss of integrity on the local system when reverse mirroring is used. A remote attacker may trick a user to use reverse mirroring on an attacker controlled FTP server, resulting in the removal of all files in the current working directory of the victim's system.
Published: 2018-08-01
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2018-2971 It has been discovered that lftp up to and including version 4.8.3 does not properly sanitize remote file names, leading to a loss of integrity on the local system when reverse mirroring is used. A remote attacker may trick a user to use reverse mirroring on an attacker controlled FTP server, resulting in the removal of all files in the current working directory of the victim's system.
Ubuntu USN Ubuntu USN USN-3731-1 LFTP vulnerability
Ubuntu USN Ubuntu USN USN-3731-2 LFTP vulnerability
History

No history.

Subscriptions

Canonical Ubuntu Linux
Lftp Project Lftp
Opensuse Leap
Redhat Enterprise Linux
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-05T07:54:35.215Z

Reserved: 2018-05-09T00:00:00.000Z

Link: CVE-2018-10916

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-08-01T14:29:00.440

Modified: 2024-11-21T03:42:17.803

Link: CVE-2018-10916

cve-icon Redhat

Severity : Moderate

Publid Date: 2018-05-16T00:00:00Z

Links: CVE-2018-10916 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses