Back

HIGH

lftp: multiple HTTP client download filename vulnerability [OCERT 2010-001]

Published Jul 6, 2010

Description

The get1 command, as used by lftpget, in LFTP before 4.0.6 does not properly validate a server-provided filename before determining the destination filename of a download, which allows remote servers to create or overwrite arbitrary files via a Content-Disposition header that suggests a crafted filename, and possibly execute arbitrary code as a consequence of writing to a dotfile in a home directory.

Affected products

Remediation

Red Hat statement

This issue did not affect the version of lftp as shipped with Red Hat Enterprise Linux 3 and 4 as they did not include support for renaming files to a server-suggested file name.

Metrics

References (18)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jul 6, 2010
Updated Aug 7, 2024
Reserved Jun 9, 2010
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Moderate
Public date May 17, 2010