It has been discovered that lftp up to and including version 4.8.3 does not properly sanitize remote file names, leading to a loss of integrity on the local system when reverse mirroring is used. A remote attacker may trick a user to use reverse mirroring on an attacker controlled FTP server, resulting in the removal of all files in the current working directory of the victim's system.
2018-08-01T14:29:00.440
2024-11-21T03:42:17.803
Modified
CVSSv3.0: 5.3 (MEDIUM)
AV:N/AC:M/Au:N/C:N/I:P/A:C
8.6
7.8
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | lftp_project | lftp | ≤ 4.8.3 | Yes |
Operating System | canonical | ubuntu_linux | 12.04 | Yes |
Operating System | opensuse | leap | 42.3 | Yes |