Alerts This Week
Warning Icon 1 666
Alerts This Week
Warning Icon 1 666

Slackware 8.1-9.1: SSA:2003-346-01 Critical: lftp Html Parsing Threat

slackware
Calendar Grey December 12, 2003
Dist Slackware Esm H88
Resolved lftp vulnerabilities in FTP and HTTP protocols applicable to Slackware versions 8.1 through 9.1, with updated packages now accessible.
lftp is a file transfer program that connects to other hosts using FTP, HTTP, and other protocols

Summary

Here are the details from the Slackware 9.1 ChangeLog: Fri Dec 12 11:12:05 PST 2003 patches/packages/lftp-2.6.10-i486-1.tgz: Upgraded to lftp-2.6.10. According to the NEWS file, this includes "security fixes in html parsing code" which could cause a compromise when using lftp to access an untrusted site. (* Security fix *) WHERE TO FIND THE NEW PACKAGE: Updated package for Slackware 8.1: ftp://ftp.slackware.com/pub/slackware/slackware-8.1/patches/packages/lftp-2.6.10-i386-1.tgz Updated package for Slackware 9.0: ftp://ftp.slackware.com/pub/slackware/slackware-9.0/patches/packages/lftp-2.6.10-i386-1.tgz Updated package for Slackware 9.1: ftp://ftp.slackware.com/pub/slackware/slackware-9.1/patches/packages/lftp-2.6.10-i486-1.tgz Updated package for Slackware -current: MD5 SIGNATURES: Slackware 8.1 package: 1e7eae2a8279491d439f4494c8733aa2 lftp-2.6.10-i386-1.tgz Slackware 9.0 package: af80878951917a6683bc3076947f2632 lftp-2.6.10-i386-1.tgz Slackware 9.1

Read the Full Advisory

Where Find New Packages

MD5 Signatures

Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Installation Instructions

Related News

Your message here