PT-2002-2272 · Ncftp+2 · Ncftp+3
Published
2002-12-17
·
Updated
2018-10-30
·
CVE-2002-1345
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
No specific software name or versions are mentioned, so the description is:
UNIX systems (affected versions not specified)
Description:
The issue concerns directory traversal vulnerabilities in multiple FTP clients on UNIX systems. These vulnerabilities allow remote malicious FTP servers to create or overwrite files as the client user via filenames containing
/absolute/path or .. (dot dot) sequences.Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ncftp
Openbsd
Solaris
Sunos