PT-2009-2485 · Netbsd · Tnftpd

Published

2009-08-21

·

Updated

2017-08-17

·

CVE-2008-7016

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions tnftpd versions prior to 20080929
Description The issue allows remote attackers to conduct cross-site request forgery (CSRF) attacks. This is achieved by splitting large command strings into multiple commands, probably involving a crafted ftp:// link to a tnftpd server.
Recommendations For versions prior to 20080929, update to a version released after 20080929 to resolve the issue. As a temporary workaround, consider restricting access to the tnftpd server to minimize the risk of exploitation.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-7016

Affected Products

Tnftpd