CVE-2002-1345: Medium severity ncftp software ncftp vulnerability
Directory traversal vulnerabilities in multiple FTP clients on UNIX systems allow remote malicious FTP servers to create or overwrite files as the client user via filenames containing /absolute/path or .. (dot dot) sequences.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2002-1345?
CVE-2002-1345 is considered to have a moderate severity due to its ability to allow file creation and overwriting by remote FTP servers.
How do I fix CVE-2002-1345?
To fix CVE-2002-1345, users should upgrade to the latest version of the affected NcFTP software or apply available patches.
Which versions are affected by CVE-2002-1345?
CVE-2002-1345 affects NcFTP versions 3.0.0 through 3.1.4 on UNIX systems.
Can CVE-2002-1345 lead to data loss?
Yes, CVE-2002-1345 can lead to data loss since it allows remote servers to overwrite files on the client system.
Is CVE-2002-1345 present in OpenBSD systems?
Yes, CVE-2002-1345 can affect OpenBSD systems that utilize the vulnerable versions of NcFTP.