Lucene search

K
osvGoogleOSV:DSA-377
HistorySep 04, 2003 - 12:00 a.m.

wu-ftpd - insecure program execution

2003-09-0400:00:00
Google
osv.dev
7

EPSS

0.125

Percentile

95.5%

wu-ftpd, an FTP server, implements a feature whereby multiple files
can be fetched in the form of a dynamically constructed archive file,
such as a tar archive. The names of the files to be included are
passed as command line arguments to tar, without protection against
them being interpreted as command-line options. GNU tar supports
several command line options which can be abused, by means of this
vulnerability, to execute arbitrary programs with the privileges of
the wu-ftpd process.

Georgi Guninski pointed out that this vulnerability exists in Debian
woody.

For the stable distribution (woody) this problem has been fixed in
version 2.6.2-3woody2.

For the unstable distribution (sid) this problem will be fixed soon.

We recommend that you update your wu-ftpd package.