CVE-2018-10916
It has been discovered that lftp up to and including version 4.8.3 does not properly sanitize remote file names, leading to a loss of integrity on the local system when reverse mirroring is used.
Does this matter?
Lower severity and a low EPSS score (4.78%). Track it; it rarely justifies an emergency change on its own.
Description
It has been discovered that lftp up to and including version 4.8.3 does not properly sanitize remote file names, leading to a loss of integrity on the local system when reverse mirroring is used. A remote attacker may trick a user to use reverse mirroring on an attacker controlled FTP server, resulting in the removal of all files in the current working directory of the victim's system.
- CVSS 3.0
- 6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
- EPSS
- 4.78% probability · 91th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- lftp project/lftp · canonical/ubuntu linux · opensuse/leap
- Source
- secalert@redhat.com
References
- http://lists.opensuse.org/opensuse-security-announce/2019-03/msg00036.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00010.html
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10916Issue Tracking, Patch, Third Party Advisory
- https://github.com/lavv17/lftp/commit/a27e07d90a4608ceaf928b1babb27d4d803e1992Patch, Third Party Advisory
- https://github.com/lavv17/lftp/issues/452Exploit, Third Party Advisory
- https://usn.ubuntu.com/3731-2/Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-03/msg00036.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00010.html
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10916Issue Tracking, Patch, Third Party Advisory
- https://github.com/lavv17/lftp/commit/a27e07d90a4608ceaf928b1babb27d4d803e1992Patch, Third Party Advisory
- https://github.com/lavv17/lftp/issues/452Exploit, Third Party Advisory
- https://usn.ubuntu.com/3731-2/Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.