PT-2002-2957 · Netbsd · Netbsd

Publicado

2002-12-31

·

Atualizado

2008-09-05

·

CVE-2002-2245

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: NetBSD versions 1.5 through 1.5.3 NetBSD version 1.6
Description: The issue arises from the ftpd in NetBSD not properly quoting a digit in response to a STAT command for a filename that contains a carriage return followed by a digit. This can cause firewalls and other intermediary devices to lose proper track of the FTP session.
Recommendations: For NetBSD versions 1.5 through 1.5.3, consider updating to a version that properly handles the STAT command response. For NetBSD version 1.6, consider updating to a version that properly handles the STAT command response. As a temporary workaround, consider restricting the use of filenames that contain carriage returns followed by digits to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2002-2245

Produtos afetados

Netbsd