Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

Gentoo 200312-07 Minimal: Lftp Buffer Overflow Remote Code Execution

gentoo
Calendar Grey December 18, 2003
Dist Gentoo Esm H88
Various security issues in lftp could enable attackers to run arbitrary code from a distance. It is recommended to update to the latest version to mitigate potential threats.
Two buffer overflow problems have been found in lftp, a multithreadedcommand-line based FTP client.

Summary


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- -------------------------------------------------------------------------- GENTOO LINUX SECURITY ANNOUNCEMENT 200312-07 - --------------------------------------------------------------------------
GLSA: 200312-07 Package: net-ftp/lftp Summary: Two buffer overflow problems found in lftp Severity: minimal Gentoo bug: 35866 Date: 2003-12-16 CVE: CAN-2003-0963 Exploit: remote Affected: <=2.6.9 Fixed: >=2.6.10

DESCRIPTION:
Two buffer overflow problems have been found in lftp, a multithreaded command-line based FTP client. A specially created directory on a web server could be used to execute arbitrary code on the connecting machine. The user's machine has to connect to a malicious web server using HTTP or HTTPS, then issue an "ls" or "rels" command.
Please see < for more details on this problem.

SOLUTION:
All machines which have net-ftp/lftp installed should be updated to use versio...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns


Warning: Undefined array key "advisory_info" in /var/www/www.linuxsecurity.com-443/html/tmp/regularlabs/custom_php/70359_4c9dbbdde36eef04251a4ced7eac4df9 on line 11

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround

Related News

Your message here