|
|
Info |
Last Modified |
| 5 months ago |
|
|
|
|
Description |
NcFTP contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is triggered due to a flaw in the automatic download option. It is possible that the flaw may allow an remote attacker to execute arbitrary commands via shell metacharacters in the names of files that are to be downloaded, resulting in a loss of integrity
|
|
Classification |
Location:
Remote/Network Access Required
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Exploit:
Exploit Unknown
Disclosure:
OSVDB Verified
|
|
Solution |
Upgrade to version 2.4.3-1 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.
|
|
Products |
|
NcFTP
 |
2.4.2 |
|
|
|
|
Credit |
- Michal Zalewski - lcamtuf
boss.staszic.waw.pl -
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|