Lucene search

K
freebsdFreeBSD2D8CF857-81EA-11D9-A9E7-0001020EED82
HistoryFeb 04, 2005 - 12:00 a.m.

gftp -- directory traversal vulnerability

2005-02-0400:00:00
vuxml.freebsd.org
13

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

EPSS

0.948

Percentile

99.3%

A Debian Security Advisory reports:

Albert Puigsech Galicia discovered a directory traversal
vulnerability in a proprietary FTP client (CAN-2004-1376)
which is also present in gftp, a GTK+ FTP client. A
malicious server could provide a specially crafted
filename that could cause arbitrary files to be
overwritten or created by the client.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchgftp< 2.0.18UNKNOWN

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

EPSS

0.948

Percentile

99.3%