PT-2005-5579 · Debian+1 · Gftp-Gtk+5
Albert Puigsech Galicia
·
Published
1970-01-01
·
Updated
2023-08-03
·
CVE-2005-0372
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
gftp versions prior to 2.0.18
gftp-common (affected versions not specified)
gftp-gtk (affected versions not specified)
gftp-text (affected versions not specified)
Description
The issue concerns multiple vulnerabilities in the gftp package of the Debian GNU/Linux operating system, which can lead to a breach of protected information. These vulnerabilities can be exploited remotely. Specifically, a directory traversal vulnerability in gftp before version 2.0.18 for GTK+ allows remote malicious FTP servers to read arbitrary files via .. (dot dot) sequences in filenames returned from a LIST command, such as
/api/ftp/list.Recommendations
For gftp versions prior to 2.0.18, update to version 2.0.18 or later to resolve the issue.
For gftp-common, gftp-gtk, and gftp-text, at the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to the vulnerable components until a patch is available. Avoid using the
LIST command in the affected API endpoint until the issue is resolved.Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Red Hat
Gftp
Gftp-Common
Gftp-Gtk
Gftp-Text