CVE Vulnerabilities

CVE-2023-45198

Published: Oct 05, 2023 | Modified: Oct 11, 2023
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

ftpd before NetBSD-ftpd 20230930 can leak information about the host filesystem before authentication via an MLSD or MLST command. tnftpd (the portable version of NetBSD ftpd) before 20231001 is also vulnerable.

Affected Software

Name Vendor Start Version End Version
Ftpd Netbsd * 2023-09-30 (excluding)
Tnftpd Netbsd * 2023-10-01 (excluding)

References