Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 544
Alerts This Week
Warning Icon 1 544

Gentoo: GLSA 200501-24 Normal Severity: Tnftp Arbitrary File Overwrite

gentoo
Calendar Grey January 14, 2005
Scroller Gentoo
Gentoo Security Notice GLSA 202309-15: tftp client susceptible to unauthorized file access. Immediate action suggested to safeguard environments.
tnftp fails to validate filenames when downloading files, making it vulnerable to arbitrary file overwriting.

Summary

Gentoo Linux Security Advisory GLSA 200501-24 https://security.gentoo.org/ Severity: Normal Title: tnftp: Arbitrary file overwriting Date: January 14, 2005 Bugs: #74704 ID: 200501-24

Synopsis ======= tnftp fails to validate filenames when downloading files, making it vulnerable to arbitrary file overwriting.
Background ========= tnftp is a NetBSD FTP client with several advanced features.
Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-ftp/tnftp < 20050103 >= 20050103
========== The 'mget' function in cmds.c lacks validation of the filenames that are supplied by the server.
Impact ===== An attacker running an FTP server could supply clients with malici...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround