CVE Vulnerabilities

CVE-2002-1345

Published: Dec 23, 2002 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Directory traversal vulnerabilities in multiple FTP clients on UNIX systems allow remote malicious FTP servers to create or overwrite files as the client user via filenames containing /absolute/path or .. (dot dot) sequences.

Affected Software

NameVendorStart VersionEnd Version
NcftpNcftp_software3.0.0 (including)3.0.0 (including)
NcftpNcftp_software3.0.1 (including)3.0.1 (including)
NcftpNcftp_software3.0.2 (including)3.0.2 (including)
NcftpNcftp_software3.0.3 (including)3.0.3 (including)
NcftpNcftp_software3.0.4 (including)3.0.4 (including)
NcftpNcftp_software3.1.0 (including)3.1.0 (including)
NcftpNcftp_software3.1.1 (including)3.1.1 (including)
NcftpNcftp_software3.1.2 (including)3.1.2 (including)
NcftpNcftp_software3.1.3 (including)3.1.3 (including)
NcftpNcftp_software3.1.4 (including)3.1.4 (including)

References