It was reported that tnftp, an FTP client from NetBSD, could be forced to run arbitrary commands if an output file is not specified. Full details and a patch are available from the following: http://seclists.org/oss-sec/2014/q4/459
Created tnftp tracking bugs for this issue: Affects: fedora-all [bug 1158287] Affects: epel-6 [bug 1158288] Affects: epel-7 [bug 1158289]
tnftp-20141031-1.fc20 has been pushed to the Fedora 20 stable repository. If problems still persist, please make note of it in this bug report.
tnftp-20141031-1.el7 has been pushed to the Fedora EPEL 7 stable repository. If problems still persist, please make note of it in this bug report.
tnftp-20141031-1.el6 has been pushed to the Fedora EPEL 6 stable repository. If problems still persist, please make note of it in this bug report.