| |||||||||||||
| Test Kennung: | 1.3.6.1.4.1.25623.1.0.68230 |
| Kategorie: | Ubuntu Local Security Checks |
| Titel: | Ubuntu USN-984-1 (lftp) |
| Zusammenfassung: | Ubuntu USN-984-1 (lftp) |
| Beschreibung: | The remote host is missing an update to lftp announced via advisory USN-984-1. Details follow: It was discovered that LFTP incorrectly filtered filenames suggested by Content-Disposition headers. If a user or automated system were tricked into downloading a file from a malicious site, a remote attacker could create the file with an arbitrary name, such as a dotfile, and possibly run arbitrary code. Solution: The problem can be corrected by upgrading your system to the following package versions: Ubuntu 8.04 LTS: lftp 3.6.1-1ubuntu0.1 Ubuntu 9.04: lftp 3.7.8-1ubuntu0.1 Ubuntu 9.10: lftp 3.7.15-1ubuntu2.1 Ubuntu 10.04 LTS: lftp 4.0.2-1ubuntu0.1 In general, a standard system update will make all the necessary changes. ATTENTION: This update changes previous behaviour by ignoring the filename supplied by servers in Content-Disposition headers. To re-enable previous behaviour, use the new xfer:auto-rename setting. http://www.securityspace.com/smysecure/catid.html?in=USN-984-1 Risk factor : High |
| Querverweis: |
Common Vulnerability Exposure (CVE) ID: CVE-2010-2251 Bugtraq: 20101027 rPSA-2010-0073-1 lftp (Google Search) http://www.securityfocus.com/archive/1/archive/1/514499/100/0/threaded http://marc.info/?l=oss-security&m=127411372529485&w=2 http://marc.info/?l=oss-security&m=127432968701342&w=2 http://marc.info/?l=oss-security&m=127611288927500&w=2 http://marc.info/?l=oss-security&m=127620248914170&w=2 http://www.ocert.org/advisories/ocert-2010-001.html Debian Security Information: DSA-2085 (Google Search) http://www.debian.org/security/2010/dsa-2085 http://lists.fedoraproject.org/pipermail/package-announce/2010-June/043597.html SuSE Security Announcement: SUSE-SR:2010:014 (Google Search) http://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.html http://secunia.com/advisories/40400 http://www.vupen.com/english/advisories/2010/1654 |
| Copyright | Copyright (c) 2010 E-Soft Inc. http://www.securityspace.com |
| Dies ist nur einer von 32582 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus. Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten. |
|