LFTP Man In The Middle Information Disclosure Vulnerability
BID:73100
Info
LFTP Man In The Middle Information Disclosure Vulnerability
| Bugtraq ID: | 73100 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 12 2015 12:00AM |
| Updated: | Apr 13 2015 09:38PM |
| Credit: | Marcin Szewczyk |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
LFTP Man In The Middle Information Disclosure Vulnerability
LFTP is prone to an information disclosure vulnerability.
An attacker can exploit this issue to perform man-in-the-middle attacks and obtain sensitive information. Successful exploits will lead to other attacks.
LFTP is prone to an information disclosure vulnerability.
An attacker can exploit this issue to perform man-in-the-middle attacks and obtain sensitive information. Successful exploits will lead to other attacks.
Exploit / POC
LFTP Man In The Middle Information Disclosure Vulnerability
An attacker may use readily available tools to exploit this issue.
An attacker may use readily available tools to exploit this issue.
Solution / Fix
LFTP Man In The Middle Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
LFTP Man In The Middle Information Disclosure Vulnerability
References:
References:
- CVE request: lftp saves unknown host's fingerprint in known_hosts without any pr (Vasyl Kaigorodov)
- LFTP Homepage (LFTP)