PT-2018-2667 · Lftp+5 · Lftp+5
Tomsommero
·
Published
2018-08-01
·
Updated
2024-06-15
·
CVE-2018-10916
CVSS v2.0
7.8
High
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:C |
Name of the Vulnerable Software and Affected Versions
lftp versions up to and including 4.8.3
Description
The issue arises from lftp's failure to properly sanitize remote file names, leading to a loss of integrity on the local system when reverse mirroring is used. A remote attacker may trick a user into using reverse mirroring on an attacker-controlled FTP server, resulting in the removal of all files in the current working directory of the victim's system. This is due to insufficient input validation in the console FTP client.
Recommendations
For lftp versions up to and including 4.8.3, avoid using reverse mirroring with untrusted FTP servers to minimize the risk of exploitation. As a temporary workaround, consider restricting the use of reverse mirroring until a patch is available.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Centos
Red Hat
Suse
Ubuntu
Lftp