Lftp · Lftp · CVE-2018-10916
**Name of the Vulnerable Software and Affected Versions**
lftp versions up to and including 4.8.3
**Description**
The issue arises from lftp's failure to properly sanitize remote file names, leading to a loss of integrity on the local system when reverse mirroring is used. A remote attacker may trick a user into using reverse mirroring on an attacker-controlled FTP server, resulting in the removal of all files in the current working directory of the victim's system. This is due to insufficient input validation in the console FTP client.
**Recommendations**
For lftp versions up to and including 4.8.3, avoid using reverse mirroring with untrusted FTP servers to minimize the risk of exploitation. As a temporary workaround, consider restricting the use of reverse mirroring until a patch is available.