UBUNTU-CVE-2018-10916
Dashboard / Vulnerabilities / UBUNTU-CVE-2018-10916
UBUNTU-CVE-2018-10916
Summary:
Details: It has been discovered that lftp up to and including version 4.8.3 does not properly sanitize remote file names, leading to a loss of integrity on the local system when reverse mirroring is used. A remote attacker may trick a user to use reverse mirroring on an attacker controlled FTP server, resulting in the removal of all files in the current working directory of the victim's system.
References: https://ubuntu.com/security/CVE-2018-10916, https://ubuntu.com/security/notices/USN-3731-1, https://ubuntu.com/security/notices/USN-3731-2, https://www.cve.org/CVERecord?id=CVE-2018-10916
Affected packages
Package
Name: lftp
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
