[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248364

 
 

909

 
 

195388

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2018-10916Date: (C)2018-08-03   (M)2023-12-22


It has been discovered that lftp up to and including version 4.8.3 does not properly sanitize remote file names, leading to a loss of integrity on the local system when reverse mirroring is used. A remote attacker may trick a user to use reverse mirroring on an attacker controlled FTP server, resulting in the removal of all files in the current working directory of the victim's system.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : 6.5CVSS Score : 7.8
Exploit Score: 2.8Exploit Score: 8.6
Impact Score: 3.6Impact Score: 7.8
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: NETWORKAccess Vector: NETWORK
Attack Complexity: LOWAccess Complexity: MEDIUM
Privileges Required: NONEAuthentication: NONE
User Interaction: REQUIREDConfidentiality: NONE
Scope: UNCHANGEDIntegrity: PARTIAL
Confidentiality: NONEAvailability: COMPLETE
Integrity: HIGH 
Availability: NONE 
  
Reference:
USN-3731-2
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10916
https://github.com/lavv17/lftp/commit/a27e07d90a4608ceaf928b1babb27d4d803e1992
https://github.com/lavv17/lftp/issues/452
openSUSE-SU-2019:1059
openSUSE-SU-2019:1110

CPE    1
cpe:/o:canonical:ubuntu_linux:12.04::~~esm~~~
CWE    1
CWE-20
OVAL    10
oval:org.secpod.oval:def:1601152
oval:org.secpod.oval:def:503611
oval:org.secpod.oval:def:89003462
oval:org.secpod.oval:def:2103548
...

© SecPod Technologies