Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Jared Mcneill

#36023de 53,638
7.5CVSS total
Vulnerabilidades · 1
PT-2014-8580
7.5
2014-11-17
Netbsd · Tnftp · CVE-2014-8517
**Name of the Vulnerable Software and Affected Versions** tnftp versions 5.1 through 5.1.4 tnftp versions 5.2 through 5.2.2 tnftp versions 6.0 through 6.0.6 tnftp versions 6.1 through 6.1.5 **Description** The issue allows remote attackers to execute arbitrary commands via a | (pipe) character at the end of an HTTP redirect. This is due to a problem in the `fetch url` function in `usr.bin/ftp/fetch.c`. **Recommendations** For versions 5.1 through 5.1.4, update to a version that fixes the issue in the `fetch url` function. For versions 5.2 through 5.2.2, update to a version that fixes the issue in the `fetch url` function. For versions 6.0 through 6.0.6, update to a version that fixes the issue in the `fetch url` function. For versions 6.1 through 6.1.5, update to a version that fixes the issue in the `fetch url` function.