Junkie FTP Client Server Response Download Filename File Corruption Vulnerability
BID:12011
Info
Junkie FTP Client Server Response Download Filename File Corruption Vulnerability
| Bugtraq ID: | 12011 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 15 2004 12:00AM |
| Updated: | Dec 15 2004 12:00AM |
| Credit: | Yosef Klein is credited with the discovery of this issue. |
| Vulnerable: |
junkie FTP Client 0.3.1 |
| Not Vulnerable: | |
Discussion
Junkie FTP Client Server Response Download Filename File Corruption Vulnerability
junkie FTP client does not properly sanitize server-supplied filenames during downloads, potentially allowing for files to be created or overwritten in the context of the client user.
junkie FTP client does not properly sanitize server-supplied filenames during downloads, potentially allowing for files to be created or overwritten in the context of the client user.
Exploit / POC
Junkie FTP Client Server Response Download Filename File Corruption Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Junkie FTP Client Server Response Download Filename File Corruption Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Junkie FTP Client Server Response Download Filename File Corruption Vulnerability
References:
References:
- [remote] [control] junkie 0.3.1 gui_popup_view_fly does not check for nasty char ("D. J. Bernstein"
) - junkie FTP Client Home Page (junkie)