Alerts This Week
Warning Icon 1 684
Alerts This Week
Warning Icon 1 684

Gentoo: GLSA-202301-14 Critical: curl Unsafe Protocol Handling

gentoo
Calendar Grey December 18, 2003
Dist Gentoo Esm H88
A couple of security vulnerabilities in Gentoo's lftp could lead to remote code execution. It's recommended to update to version 2.6.10 or above for protection.
Two buffer overflow problems have been found in lftp, a multithreaded command-line based FTP client

Summary


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
- --------------------------------------------------------------------------
GENTOO LINUX SECURITY ANNOUNCEMENT 200312-07
- --------------------------------------------------------------------------

GLSA: 200312-07 Package: net-ftp/lftp Summary: Two buffer overflow problems found in lftp Severity: minimal Gentoo bug: 35866 Date: 2003-12-16 CVE: CAN-2003-0963 Exploit: remote Affected: <=2.6.9 Fixed: >=2.6.10
DESCRIPTION:
Two buffer overflow problems have been found in lftp, a multithreaded command-line based FTP client. A specially created directory on a web server could be used to execute arbitrary code on the connecting machine. The user's machine has to connect to a malicious web server using HTTP or HTTPS, then issue an "ls" or "rels" command.
Please see <> for more details on this problem.
SOLUTION:
All machines which have net-ftp/lftp installed should be updated to use version 2.6.10 or higher using these commands:
...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Severity
critical
Lowest
Low
Medium
High
Critical


Warning: Undefined array key "advisory_info" in /var/www/www.linuxsecurity.com-443/html/tmp/regularlabs/custom_php/3860039_4c9dbbdde36eef04251a4ced7eac4df9 on line 11

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround

Related News

Your message here