CVE-2004-1294: Medium severity Luke Mewburn Tnftp vulnerability
Published Dec 22, 2004
·Updated
The mget function in cmds.c for tnftp 20030825 allows remote FTP servers to overwrite arbitrary files via FTP responses containing file names with / (slash) characters.
Affected Software
1 affected component
Luke Mewburn Tnftp=2003-08-25
Event History
Dec 22, 2004
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-1294?
CVE-2004-1294 is considered a vulnerability of medium severity due to its potential for remote file overwrite.
2
How do I fix CVE-2004-1294?
To fix CVE-2004-1294, upgrade to a version of tnftp that has addressed this vulnerability.
3
What is the impact of CVE-2004-1294?
The impact of CVE-2004-1294 allows remote FTP servers to overwrite arbitrary files on affected systems.
4
Which versions of tnftp are affected by CVE-2004-1294?
CVE-2004-1294 affects tnftp version 2003-08-25.
5
Is CVE-2004-1294 easy to exploit?
Yes, CVE-2004-1294 can be easily exploited by attackers with access to remote FTP servers, potentially allowing file manipulation.