PT-2005-5579 · Debian+1 · Gftp-Gtk+5

·

CVE-2005-0372

·

Published

1970-01-01

·

Updated

2023-08-03

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions gftp versions prior to 2.0.18 gftp-common (affected versions not specified) gftp-gtk (affected versions not specified) gftp-text (affected versions not specified)
Description The issue concerns multiple vulnerabilities in the gftp package of the Debian GNU/Linux operating system, which can lead to a breach of protected information. These vulnerabilities can be exploited remotely. Specifically, a directory traversal vulnerability in gftp before version 2.0.18 for GTK+ allows remote malicious FTP servers to read arbitrary files via .. (dot dot) sequences in filenames returned from a LIST command, such as /api/ftp/list.
Recommendations For gftp versions prior to 2.0.18, update to version 2.0.18 or later to resolve the issue. For gftp-common, gftp-gtk, and gftp-text, at the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to the vulnerable components until a patch is available. Avoid using the LIST command in the affected API endpoint until the issue is resolved.

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-02969
BDU:2015-04074
BDU:2015-04075
BDU:2015-04076
CVE-2005-0372
DSA-686-1
RHSA-2005:410
RHSA-2005_410

Affected Products

Debian
Red Hat
Gftp
Gftp-Common
Gftp-Gtk
Gftp-Text