The ftp_retr function in junkie 0.3.1 allows remote malicious FTP servers to overwrite arbitrary files via .. (dot dot) sequences in a filename.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Junkie_ftp_client |
Junkie |
0.3.1 (including) |
0.3.1 (including) |
References