CVE Vulnerabilities

CVE-2007-2348

Published: Apr 27, 2007 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
5.1 LOW
AV:N/AC:H/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
UNTRIAGED

mirror –script in lftp before 3.5.9 does not properly quote shell metacharacters, which might allow remote user-assisted attackers to execute shell commands via a malicious script. NOTE: it is not clear whether this issue crosses security boundaries, since the script already supports commands such as get which could overwrite executable files.

Affected Software

Name Vendor Start Version End Version
Lftp Alexander_v._lukyanov * 3.5.8 (including)
Red Hat Enterprise Linux 5 RedHat lftp-0:3.7.11-4.el5 *
Lftp Ubuntu dapper *
Lftp Ubuntu devel *
Lftp Ubuntu edgy *
Lftp Ubuntu feisty *

References