ftpd before "NetBSD-ftpd 20230930" can leak information about the host filesystem before authentication via an MLSD or MLST command. tnftpd (the portable version of NetBSD ftpd) before 20231001 is also vulnerable.
2023-10-05T05:15:42.257
2024-11-21T08:26:32.040
Modified
CVSSv3.1: 7.5 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | netbsd | ftpd | < 2023-09-30 | Yes |
Application | netbsd | tnftpd | < 2023-10-01 | Yes |