CVE Vulnerabilities

CVE-2014-1693

Published: Dec 08, 2014 | Modified: Mar 16, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
LOW

Multiple CRLF injection vulnerabilities in the FTP module in Erlang/OTP R15B03 allow context-dependent attackers to inject arbitrary FTP commands via CRLF sequences in the (1) user, (2) account, (3) cd, (4) ls, (5) nlist, (6) rename, (7) delete, (8) mkdir, (9) rmdir, (10) recv, (11) recv_bin, (12) recv_chunk_start, (13) send, (14) send_bin, (15) send_chunk_start, (16) append_chunk_start, (17) append, or (18) append_bin command.

Affected Software

Name Vendor Start Version End Version
Erlang/otp Erlang r15b03 (including) r15b03 (including)
Erlang Ubuntu lucid *
Erlang Ubuntu precise *
Erlang Ubuntu quantal *
Erlang Ubuntu saucy *
Erlang Ubuntu trusty *
Erlang Ubuntu upstream *

References