Bug 239334 - lftp affected by problems described in CVE-2007-2348
lftp affected by problems described in CVE-2007-2348
Status: CLOSED ERRATA
Product: Red Hat Enterprise Linux 5
Classification: Red Hat
Component: lftp (Show other bugs)
5.0
All Linux
medium Severity medium
: ---
: ---
Assigned To: Jiri Skala
http://lftp.yar.ru/news.html
impact=low,source=gentoo,reported=200...
: Security
Depends On:
Blocks: CVE-2007-2348
  Show dependency treegraph
 
Reported: 2007-05-07 13:00 EDT by Michal Jaegermann
Modified: 2014-11-09 17:30 EST (History)
3 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2009-09-02 05:37:53 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Michal Jaegermann 2007-05-07 13:00:38 EDT
Description of problem:

According to 
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2348
version of lftp used in RHEL 5 and earlier have issues with
quoting in scripts generated by 'mirror --script' and this may
cause priviledge escalation and a remote command execution
(although possibilty of such attack looks somewhat remote).

Looking at versions it appears that this lftp will be affected
by bug #211483 as well.

The same will apply to FC5; FC6 and rawhide currently sport
versions where this bug was fixed.

Version-Release number of selected component (if applicable):
lftp-3.5.1-2.fc6
Comment 2 RHEL Product and Program Management 2008-06-04 18:49:25 EDT
This request was evaluated by Red Hat Product Management for inclusion in a Red
Hat Enterprise Linux maintenance release.  Product Management has requested
further review of this request by Red Hat Engineering, for potential
inclusion in a Red Hat Enterprise Linux Update release for currently deployed
products.  This request is not yet committed for inclusion in an Update
release.
Comment 11 errata-xmlrpc 2009-09-02 05:37:53 EDT
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on therefore solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.

http://rhn.redhat.com/errata/RHSA-2009-1278.html

Note You need to log in before you can comment on or make changes to this bug.