PT-2007-2879 · Qftp+1 · Qftp+1
Published
2007-03-16
·
Updated
2024-08-07
·
CVE-2007-1485
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
LIBFtp version 3.1-1
Description
A buffer overflow issue exists in the set umask function in QFTP, allowing local users to potentially execute arbitrary code via a long -m argument. However, it is noted that QFTP is not setuid, and it is unlikely that there are web interfaces to QFTP that would accept untrusted command line arguments.
Recommendations
For LIBFtp version 3.1-1, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Libftp
Qftp