UBUNTU-CVE-2014-1693
Dashboard / Vulnerabilities / UBUNTU-CVE-2014-1693
UBUNTU-CVE-2014-1693
Summary:
Details: Multiple CRLF injection vulnerabilities in the FTP module in Erlang/OTP R15B03 allow context-dependent attackers to inject arbitrary FTP commands via CRLF sequences in the (1) user, (2) account, (3) cd, (4) ls, (5) nlist, (6) rename, (7) delete, (8) mkdir, (9) rmdir, (10) recv, (11) recv_bin, (12) recv_chunk_start, (13) send, (14) send_bin, (15) send_chunk_start, (16) append_chunk_start, (17) append, or (18) append_bin command.
References: https://ubuntu.com/security/CVE-2014-1693, http://www.openwall.com/lists/oss-security/2014/01/29/3, http://www.openwall.com/lists/oss-security/2014/01/29, http://erlang.org/pipermail/erlang-bugs/2014-January/003998.html, https://ubuntu.com/security/notices/USN-3571-1, https://www.cve.org/CVERecord?id=CVE-2014-1693
Affected packages
Package
Name: erlang
Purl: pkg:deb/ubuntu/erlang@1:16.b.3-dfsg-1ubuntu2.2?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
