posts - 27,  comments - 2,  trackbacks - 0

-------------------------------------------------------------------
受影响系统:
Core FTP Core FTP LE/PRO 2.1 Build 1565
不受影响系统:
Core FTP Core FTP LE/PRO 2.1 Build 1568

-------------------------------------------------------------------
Description:
Tan Chew Keong has reported a vulnerability in Core FTP, which can be exploited by malicious people to compromise a user's system.

The vulnerability is caused due to an input validation error when downloading directories containing files with directory traversal specifiers in the filename. This can be exploited to download files to an arbitrary location on a user's system.

Successful exploitation requires that the user is tricked into connecting and downloading a directory from a malicious FTP server.

The vulnerability is reported in Core FTP LE/PRO version 2.1 Build 1565

Do you have this product installed on your home computer? Scan using the free Personal Software Inspector. Check if a vulnerable version is installed on computers in your corporate network, scan using the Network Software Inspector.

Solution:
Update to version 2.1 Build 1568.

Provided and/or discovered by:
Tan Chew Keong

厂商补丁:

Core FTP
--------
目前厂商已经发布了升级补丁以修复这个安全问题,请到厂商的主页下载:

http://www.coreftp.com/

posted on 2008-05-29 00:28 Vhk 阅读(344) 评论(0)  编辑 收藏 引用
只有注册用户登录后才能发表评论。
<2008年5月>
27282930123
45678910
11121314151617
18192021222324
25262728293031
1234567

常用链接

留言簿(4)

随笔分类

随笔档案

相册

我的链接

朋友圈链

搜索

  •  

最新评论

阅读排行榜

评论排行榜