PT-2014-4296 · Erlang+1 · Erlang/Otp+1
Publicado
2014-12-08
·
Atualizado
2018-03-16
·
CVE-2014-1693
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Erlang/OTP version R15B03
Description
The issue allows context-dependent attackers to inject arbitrary FTP commands via CRLF sequences in various commands, including
user, account, cd, ls, nlist, rename, delete, mkdir, rmdir, recv, recv bin, recv chunk start, send, send bin, send chunk start, append chunk start, append, and append bin.Recommendations
For Erlang/OTP version R15B03, consider disabling the FTP module until a patch is available to prevent exploitation. Restrict access to the vulnerable commands to minimize the risk of arbitrary FTP command injection. Avoid using the affected commands in the FTP module until the issue is resolved.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Erlang/Otp
Ubuntu