VDB
CVE-2010-2251
CVE-2010-2251
PUBLISHED
CVSS 7.5 HIGH
The get1 command, as used by lftpget, in LFTP before 4.0.6 does not properly validate a server-provided filename before determining the destination filename of a download, which allows remote servers to create or overwrite arbitrary files via a Content-Disposition header that suggests a crafted filename, and possibly execute arbitrary code as a consequence of writing to a dotfile in a home directory.
EPSS 2.42% · 85.4th percentile
Risk Scores
CVSS 2.0
7.5
EPSS Score
2.42%
85.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| alexander_v._lukyanov | lftp | 3.0.4, 0, 2.0.0 |
| n/a | n/a | n/a |
Timeline
- Jul 6, 2010 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 14, 2022 CVE Updated
- May 20, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
References
- http://lists.fedoraproject.org/pipermail/package-announce/2010-June/043597.html technical
- http://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.html technical
- http://marc.info/?l=oss-security&m=127411372529485&w=2 technical
- http://marc.info/?l=oss-security&m=127432968701342&w=2 technical
- http://marc.info/?l=oss-security&m=127611288927500&w=2 technical
- http://marc.info/?l=oss-security&m=127620248914170&w=2 technical
- http://secunia.com/advisories/40400 technical
- http://wiki.rpath.com/Advisories:rPSA-2010-0073 technical
- http://www.debian.org/security/2010/dsa-2085 technical
- http://www.ocert.org/advisories/ocert-2010-001.html technical
- http://www.securityfocus.com/archive/1/514499/100/0/threaded technical
- http://www.vupen.com/english/advisories/2010/1654 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=591580 technical
- https://bugzilla.redhat.com/show_bug.cgi?id=602836 technical
- https://nvd.nist.gov/vuln/detail/CVE-2010-2251 advisory
- http://lftp.yar.ru/news.html url