Get a Pentest and security assessment of your IT network.

Advisories

Mandriva Linux Security Advisory 2010-128

Mandriva Linux Security Advisory 2010-128 – The get1 command, as used by lftpget, in LFTP before 4.0.6 does not properly validate a server-provided filename before determining the destination filename of a download, which allows remote servers to create or overwrite arbitrary files via a Content-Disposition header that suggests a crafted filename, and possibly execute arbitrary code as a consequence of writing to a dotfile in a home directory. The updated packages have been patched to correct this issue.

 

You can download this advisory from the following link: https://packetstormsecurity.com/files/download/91567/MDVSA-2010-128.txt

Source: https://packetstormsecurity.com/files/91567/Mandriva-Linux-Security-Advisory-2010-128.html

Related posts
Advisories

57657.html

Advisories

Secunia Security Advisory 17317

Advisories

Ubuntu Security Notice 284-1

Advisories

Hardened-PHP Project Security Advisory 2006-14.139