Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

Mageia 7: 2019-0417 Moderate: FileZilla Command Injection

mageia
Calendar Grey December 31, 2019
Dist Mageia Esm H88
The revised FileZilla releases tackle vulnerabilities concerning file naming protocols effective January 1, 2020.
Updated filezilla packages fix bugs and a security vulnerability: Filenames containing double-quotation marks were not escaped correctly when selected for opening/editing

Summary

Updated filezilla packages fix bugs and a security vulnerability: Filenames containing double-quotation marks were not escaped correctly when selected for opening/editing. Depending on the associated program, parts of the filename could be interpreted as commands.

References

- https://bugs.mageia.org/show_bug.cgi?id=25932

- https://filezilla-project.org/versions.php

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/DYM7BZFULYL5BCP2SHUMLBOW2W6CDWPX/

Resolution

SRPMS

- 7/core/filezilla-3.46.3-1.mga7

- 7/core/libfilezilla-0.19.3-1.mga7

Publication date: 31 Dec 2019
URL: https://advisories.mageia.org/MGASA-2019-0417.html
Type: security

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here