Bug 1059331 (CVE-2014-1693) - CVE-2014-1693 erlang-inets: command injection flaw in FTP module
Summary: CVE-2014-1693 erlang-inets: command injection flaw in FTP module
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2014-1693
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1059333 1059335
Blocks:
TreeView+ depends on / blocked
 
Reported: 2014-01-29 16:24 UTC by Martin Prpič
Modified: 2019-09-29 13:13 UTC (History)
8 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2015-04-23 07:04:00 UTC


Attachments (Terms of Use)

Description Martin Prpič 2014-01-29 16:24:59 UTC
An FTP command injection flaw was found [1] in Erlang's FTP module. Several functions in the FTP module do not properly sanitize the input before passing it into a control socket. A local attacker can use this flaw to execute arbitrary FTP commands on a system that uses this module.

This issue has been reported upstream [2], but has not yet been fixed.

[1] http://seclists.org/oss-sec/2014/q1/163
[2] http://erlang.org/pipermail/erlang-bugs/2014-January/003998.html

Comment 1 Martin Prpič 2014-01-29 16:28:30 UTC
Created erlang tracking bugs for this issue:

Affects: fedora-all [bug 1059333]
Affects: epel-all [bug 1059335]

Comment 2 Fedora Update System 2014-12-01 18:57:02 UTC
erlang-R16B-03.9.fc20 has been pushed to the Fedora 20 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 3 Fedora Update System 2014-12-15 04:27:03 UTC
erlang-R16B-03.10.fc20 has been pushed to the Fedora 20 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 4 Fedora Update System 2014-12-20 00:18:33 UTC
erlang-R16B-03.10.el7 has been pushed to the Fedora EPEL 7 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 5 Fedora Update System 2014-12-23 18:32:54 UTC
erlang-17.4-1.fc21 has been pushed to the Fedora 21 stable repository.  If problems still persist, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.