posts - 27,  comments - 2,  trackbacks - 0

-------------------------------------------------------------------
受影响系统:
Core FTP Core FTP LE/PRO 2.1 Build 1565
不受影响系统:
Core FTP Core FTP LE/PRO 2.1 Build 1568

-------------------------------------------------------------------
Description:
Tan Chew Keong has reported a vulnerability in Core FTP, which can be exploited by malicious people to compromise a user's system.

The vulnerability is caused due to an input validation error when downloading directories containing files with directory traversal specifiers in the filename. This can be exploited to download files to an arbitrary location on a user's system.

Successful exploitation requires that the user is tricked into connecting and downloading a directory from a malicious FTP server.

The vulnerability is reported in Core FTP LE/PRO version 2.1 Build 1565

Do you have this product installed on your home computer? Scan using the free Personal Software Inspector. Check if a vulnerable version is installed on computers in your corporate network, scan using the Network Software Inspector.

Solution:
Update to version 2.1 Build 1568.

Provided and/or discovered by:
Tan Chew Keong

厂商补丁:

Core FTP
--------
目前厂商已经发布了升级补丁以修复这个安全问题,请到厂商的主页下载:

http://www.coreftp.com/

posted on 2008-05-29 00:28 Vhk 阅读(344) 评论(0)  编辑 收藏 引用
只有注册用户登录后才能发表评论。
<2024年4月>
31123456
78910111213
14151617181920
21222324252627
2829301234
567891011

常用链接

留言簿(4)

随笔分类

随笔档案

相册

我的链接

朋友圈链

搜索

  •  

最新评论

阅读排行榜

评论排行榜