LFTP 'Content-Disposition' HTTP Header Arbitrary File Overwrite Vulnerability
BID:43728
Info
LFTP 'Content-Disposition' HTTP Header Arbitrary File Overwrite Vulnerability
| Bugtraq ID: | 43728 |
| Class: | Input Validation Error |
| CVE: |
CVE-2010-2251 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 04 2010 12:00AM |
| Updated: | May 07 2015 05:06PM |
| Credit: | Hank Leininger and Solar Designer |
| Vulnerable: |
S.u.S.E. openSUSE 11.2 S.u.S.E. openSUSE 11.1 S.u.S.E. openSUSE 11.0 rPath rPath Linux 2 Redhat Enterprise Linux Desktop 5 client Redhat Enterprise Linux 5 Server Gentoo Linux Avaya Voice Portal 4.0 Avaya IQ 5.1 Avaya IQ 5 Avaya Integrated Management Suite (IMS) 0 Avaya CVLAN Avaya Aura System Manager 1.0 Avaya Aura Presence Services 6.0 Avaya Aura Presence Services 0 Avaya Aura Application Enablement Services 5.2.1 Avaya Aura Application Enablement Services 4.2.3 Avaya Aura Application Enablement Services 4.2.2 Avaya Aura Application Enablement Services 4.2.1 Avaya Aura Application Enablement Services 4.0.1 Avaya Aura Application Enablement Services 5.2 Avaya Aura Application Enablement Services 4.2 Avaya Aura Application Enablement Services 4.1 Avaya Aura Application Enablement Services 4.0 Alexander V. Lukyanov lftp 2.6.9 Alexander V. Lukyanov lftp 2.6.8 Alexander V. Lukyanov lftp 4.0.5 Alexander V. Lukyanov lftp 4.0.4 Alexander V. Lukyanov lftp 4.0.3 Alexander V. Lukyanov lftp 4.0.2 Alexander V. Lukyanov lftp 4.0.1 Alexander V. Lukyanov lftp 4.0.0 |
| Not Vulnerable: |
Alexander V. Lukyanov lftp 4.0.6 |
Discussion
LFTP 'Content-Disposition' HTTP Header Arbitrary File Overwrite Vulnerability
LFTP control is prone to an arbitrary file-overwrite vulnerability.
Attackers can overwrite arbitrary files on the victim's computer in the context of the vulnerable application using the program. Arbitrary code execution may also be possible.
Versions prior to LFTP 4.0.6 are vulnerable.
LFTP control is prone to an arbitrary file-overwrite vulnerability.
Attackers can overwrite arbitrary files on the victim's computer in the context of the vulnerable application using the program. Arbitrary code execution may also be possible.
Versions prior to LFTP 4.0.6 are vulnerable.
Exploit / POC
LFTP 'Content-Disposition' HTTP Header Arbitrary File Overwrite Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
LFTP 'Content-Disposition' HTTP Header Arbitrary File Overwrite Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
LFTP 'Content-Disposition' HTTP Header Arbitrary File Overwrite Vulnerability
References:
References:
- Avaya Homepage (Avaya Inc.)
- Debian Homepage (Debian)
- DSA-2085-1 lftp -- missing input validation (Debian)
- Fedora 12 Update: lftp-4.0.8-1.fc12 (Fedora)
- LFTP Changelog (LFTP)
- LFTP Homepage (LFTP)
- lftp security update (RHSA-2010-0585) (Avaya)
- Moderate: lftp security update (Red Hat)
- openSUSE Homepage (SUSE)
- Red Hat Homepage (Red Hat)
- SUSE Security Summary Report: SUSE-SR:2010:014 (SUSE)