Bug 149110

Summary: CAN-2005-0372 directory traversal issue in gftp
Product: [Fedora] Fedora Reporter: Josh Bressers <bressers>
Component: gftpAssignee: David Zeuthen <davidz>
Status: CLOSED ERRATA QA Contact: Mike McLean <mikem>
Severity: medium Docs Contact:
Priority: medium    
Version: 3CC: mclasen, wtogami
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard: impact=moderate,public=20050214,source=vendorsec,reported=20050214
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2005-04-08 19:06:50 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Josh Bressers 2005-02-18 20:08:28 UTC
*** This bug has been split off bug 149109 ***

------- Original comment by Josh Bressers (Security Response Team) on 2005.02.18
15:05 -------

gftp versions 2.0.18 and before have a directory traversal issue.  This issue
was reported to bugtraq in 2004, but it was not discovered in gftp until recently.

Please see:
http://www.securityfocus.com/archive/1/385882/2004-12-01/2004-12-31/0

The fix for this issue is attachment 111215 [details]

Comment 1 Josh Bressers 2005-02-18 20:10:13 UTC
This issue should also affect FC2.

Comment 4 David Zeuthen 2005-04-08 19:06:50 UTC
Fixed for both FC2 and FC3