Directory traversal vulnerabilities in multiple FTP clients on UNIX systems allow remote malicious FTP servers to create or overwrite files as the client user via filenames containing /absolute/path or .. (dot dot) sequences.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ncftp | Ncftp_software | 3.0.0 (including) | 3.0.0 (including) |
Ncftp | Ncftp_software | 3.0.1 (including) | 3.0.1 (including) |
Ncftp | Ncftp_software | 3.0.2 (including) | 3.0.2 (including) |
Ncftp | Ncftp_software | 3.0.3 (including) | 3.0.3 (including) |
Ncftp | Ncftp_software | 3.0.4 (including) | 3.0.4 (including) |
Ncftp | Ncftp_software | 3.1.0 (including) | 3.1.0 (including) |
Ncftp | Ncftp_software | 3.1.1 (including) | 3.1.1 (including) |
Ncftp | Ncftp_software | 3.1.2 (including) | 3.1.2 (including) |
Ncftp | Ncftp_software | 3.1.3 (including) | 3.1.3 (including) |
Ncftp | Ncftp_software | 3.1.4 (including) | 3.1.4 (including) |