Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Lftp
(Lftp_project)Repositories | https://github.com/lavv17/lftp |
#Vulnerabilities | 1 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2018-08-01 | CVE-2018-10916 | It has been discovered that lftp up to and including version 4.8.3 does not properly sanitize remote file names, leading to a loss of integrity on the local system when reverse mirroring is used. A remote attacker may trick a user to use reverse mirroring on an attacker controlled FTP server, resulting in the removal of all files in the current working directory of the victim's system. | Ubuntu_linux, Lftp, Leap | 6.5 |