PT-2018-2667 · Lftp+5 · Lftp+5

Tomsommero

·

Publicado

2018-08-01

·

Atualizado

2024-06-15

·

CVE-2018-10916

CVSS v2.0

7.8

Alta

VetorAV:N/AC:M/Au:N/C:N/I:P/A:C
Name of the Vulnerable Software and Affected Versions lftp versions up to and including 4.8.3
Description The issue arises from lftp's failure to properly sanitize remote file names, leading to a loss of integrity on the local system when reverse mirroring is used. A remote attacker may trick a user into using reverse mirroring on an attacker-controlled FTP server, resulting in the removal of all files in the current working directory of the victim's system. This is due to insufficient input validation in the console FTP client.
Recommendations For lftp versions up to and including 4.8.3, avoid using reverse mirroring with untrusted FTP servers to minimize the risk of exploitation. As a temporary workaround, consider restricting the use of reverse mirroring until a patch is available.

Exploit

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2018-2263
BDU:2019-01302
CESA-2020_1045
CVE-2018-10916
OPENSUSE-SU-2019:1110-1
OPENSUSE-SU-2019_1059-1
OPENSUSE-SU-2019_1110-1
OPENSUSE-SU-2024:10915-1
RHSA-2020:1045
RHSA-2020_1045
SUSE-SU-2019:0642-1
SUSE-SU-2019:0643-1
SUSE-SU-2019_0642-1
SUSE-SU-2019_0643-1
USN-3731-1
USN-3731-2

Produtos afetados

Alt Linux
Centos
Red Hat
Suse
Ubuntu
Lftp