CVE-2018-10916
published 2018-08-01CVE-2018-10916: It has been discovered that lftp up to and including version 4.8.3 does not properly sanitize remote file names, leading to a loss of integrity on the local…
PriorityP336medium6.5CVSS 3.0
AVNACLPRNUIRSUCNIHAN
EPSS
4.78%
91.0th percentile
It has been discovered that lftp up to and including version 4.8.3 does not properly sanitize remote file names, leading to a loss of integrity on the local system when reverse mirroring is used. A remote attacker may trick a user to use reverse mirroring on an attacker controlled FTP server, resulting in the removal of all files in the current working directory of the victim's system.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| debian | lftp | < lftp 4.8.4-1 (bookworm) | lftp 4.8.4-1 (bookworm) |
| lftp_project | lftp | <= 4.8.3 | — |
| lftp_project | lftp | >= 0 < 4.8.4-1 | 4.8.4-1 |
| lftp_project | lftp | >= 0 < 4.8.4-1 | 4.8.4-1 |
| lftp_project | lftp | >= 0 < 4.8.4-1 | 4.8.4-1 |
| lftp_project | lftp | >= 0 < 4.8.4-1 | 4.8.4-1 |
| opensuse | leap | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
nvdv2.07.8HIGHAV:N/AC:M/Au:N/C:N/I:P/A:C
osv6.5MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
LFTP vulnerability
vendor_ubuntu·2018-08-06
CVE-2018-10916 LFTP vulnerability
Title: LFTP vulnerability
Summary: LFTP could be made to crash if it received specially crafted file.
It was discovered that LFTP incorrectly handled certain files.
An attacker could possibly use this issue to cause a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
LFTP vulnerability
vendor_ubuntu·2018-08-06
CVE-2018-10916 LFTP vulnerability
Title: LFTP vulnerability
Summary: LFTP could be made to crash if it received specially crafted file.
USN-3731-1 fixed a vulnerability in LFTP. This update provides
the corresponding update for Ubuntu 12.04 ESM.
Original advisory details:
It was discovered that LFTP incorrectly handled certain files.
An attacker could possibly use this issue to cause a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
lftp: particular remote file names may lead to current working directory erased
vendor_redhat·2018-05-16·CVSS 5.3
CVE-2018-10916 [MEDIUM] CWE-20 lftp: particular remote file names may lead to current working directory erased
lftp: particular remote file names may lead to current working directory erased
It has been discovered that lftp up to and including version 4.8.3 does not properly sanitize remote file names, leading to a loss of integrity on the local system when reverse mirroring is used. A remote attacker may trick a user to use reverse mirroring on an attacker controlled FTP server, resulting in the removal of all files in the current working directory of the victim's system.
It has been discovered that lftp does not properly sanitize remote file names, leading to a loss of integrity on the local system when reverse mirroring is used. A remote attacker may trick a user to use reverse mirroring on an attacker-controlled FTP server, resulting in the removal of all files in the current working director
Debian
CVE-2018-10916: lftp - It has been discovered that lftp up to and including version 4.8.3 does not prop...
vendor_debian·2018·CVSS 5.3
CVE-2018-10916 [MEDIUM] CVE-2018-10916: lftp - It has been discovered that lftp up to and including version 4.8.3 does not prop...
It has been discovered that lftp up to and including version 4.8.3 does not properly sanitize remote file names, leading to a loss of integrity on the local system when reverse mirroring is used. A remote attacker may trick a user to use reverse mirroring on an attacker controlled FTP server, resulting in the removal of all files in the current working directory of the victim's system.
Scope: local
bookworm: resolved (fixed in 4.8.4-1)
bullseye: resolved (fixed in 4.8.4-1)
forky: resolved (fixed in 4.8.4-1)
sid: resolved (fixed in 4.8.4-1)
trixie: resolved (fixed in 4.8.4-1)
GHSA
GHSA-8mjf-52xq-g6h8: It has been discovered that lftp up to and including version 4
ghsa_unreviewed·2022-05-14
CVE-2018-10916 [HIGH] CWE-20 GHSA-8mjf-52xq-g6h8: It has been discovered that lftp up to and including version 4
It has been discovered that lftp up to and including version 4.8.3 does not properly sanitize remote file names, leading to a loss of integrity on the local system when reverse mirroring is used. A remote attacker may trick a user to use reverse mirroring on an attacker controlled FTP server, resulting in the removal of all files in the current working directory of the victim's system.
OSV
CVE-2018-10916: It has been discovered that lftp up to and including version 4
osv·2018-08-01·CVSS 6.5
CVE-2018-10916 [MEDIUM] CVE-2018-10916: It has been discovered that lftp up to and including version 4
It has been discovered that lftp up to and including version 4.8.3 does not properly sanitize remote file names, leading to a loss of integrity on the local system when reverse mirroring is used. A remote attacker may trick a user to use reverse mirroring on an attacker controlled FTP server, resulting in the removal of all files in the current working directory of the victim's system.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2019-03/msg00036.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-04/msg00010.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10916https://github.com/lavv17/lftp/commit/a27e07d90a4608ceaf928b1babb27d4d803e1992https://github.com/lavv17/lftp/issues/452https://usn.ubuntu.com/3731-2/http://lists.opensuse.org/opensuse-security-announce/2019-03/msg00036.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-04/msg00010.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10916https://github.com/lavv17/lftp/commit/a27e07d90a4608ceaf928b1babb27d4d803e1992https://github.com/lavv17/lftp/issues/452https://usn.ubuntu.com/3731-2/
2018-08-01
Published