LFTP Project LFTP 2.4.2

CPE Details

LFTP Project LFTP 2.4.2
2.4.2
2019-09-17
14h05 +00:00
2019-09-17
14h05 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:lftp_project:lftp:2.4.2:*:*:*:*:*:*:*

Informations

Vendor

lftp_project

Product

lftp

Version

2.4.2

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2018-10916 2018-08-01 12h00 +00:00 It has been discovered that lftp up to and including version 4.8.3 does not properly sanitize remote file names, leading to a loss of integrity on the local system when reverse mirroring is used. A remote attacker may trick a user to use reverse mirroring on an attacker controlled FTP server, resulting in the removal of all files in the current working directory of the victim's system.
6.5
Medium