MNBSD-2014-16: tnftp arbitrary command execution via crafted server response

Severity: Unknown

Affected Package: tnftp

Summary: tnftp arbitrary command execution via crafted server response

Description

A security vulnerability in tnftp/ftp(1) allowed a malicious HTTP server to cause the client to execute arbitrary commands. When the output filename began with a pipe character it was passed to popen(3), enabling command execution controlled by the remote server.

Affected Versions

tnftp

Recommendations

No specific recommendations provided.

References

Additional Information

Aliases: CVE-2014-8517

Published: October 31, 2014
Last Modified: October 31, 2014