VDB
CVE-2010-2251
CVE-2010-2251
PUBLISHED
CVSS 7.5 HIGH
The get1 command, as used by lftpget, in LFTP before 4.0.6 does not properly validate a server-provided filename before determining the destination filename of a download, which allows remote servers to create or overwrite arbitrary files via a Content-Disposition header that suggests a crafted filename, and possibly execute arbitrary code as a consequence of writing to a dotfile in a home directory.
EPSS 3.63% · 89.2th percentile
Risk Scores
CVSS 2.0
7.5
EPSS Score
3.63%
89.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| alexander_v._lukyanov | lftp | 3.0.4, 0, 2.0.0 |
| n/a | n/a | n/a |
Timeline
- Jul 6, 2010 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 21, 2022 EPSS Score
- Sep 5, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 19, 2022 EPSS Score
- Feb 10, 2023 EPSS Score
- Apr 4, 2023 EPSS Score
- May 27, 2023 EPSS Score
- Jul 19, 2023 EPSS Score
- Sep 10, 2023 EPSS Score
References
- http://marc.info/?l=oss-security&m=127432968701342&w=2 technical
- http://www.securityfocus.com/archive/1/514499/100/0/threaded technical
- http://www.vupen.com/english/advisories/2010/1654 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2010-2251 advisory
- http://lftp.yar.ru/news.html url
- http://secunia.com/advisories/40400 url
- http://www.ocert.org/advisories/ocert-2010-001.html url
- [oss-security] 20100517 [oCERT-2010-001] multiple http client unexpected download filename vulnerability mailing-list
- http://wiki.rpath.com/Advisories:rPSA-2010-0073 url
- https://bugzilla.redhat.com/show_bug.cgi?id=602836 url
- [oss-security] 20100609 Re: [oCERT-2010-001] multiple http client unexpected download filename vulnerability mailing-list
- FEDORA-2010-9819 vendor-advisory
- SUSE-SR:2010:014 vendor-advisory
- DSA-2085 vendor-advisory
- http://marc.info/?l=oss-security&m=127620248914170&w=2 technical
- https://bugzilla.redhat.com/show_bug.cgi?id=591580 technical