CVE-2005-0372: Path Traversal
Directory traversal vulnerability in gftp before 2.0.18 for GTK+ allows remote malicious FTP servers to read arbitrary files via .. (dot dot) sequences in filenames returned from a LIST command.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-0372?
CVE-2005-0372 has been classified as a medium severity vulnerability, allowing unauthorized file access through directory traversal.
How do I fix CVE-2005-0372?
To fix CVE-2005-0372, update gftp to version 2.0.18 or later, which mitigates the directory traversal vulnerability.
Which versions of gftp are affected by CVE-2005-0372?
All versions of gftp prior to 2.0.18 are affected by CVE-2005-0372.
What type of attack is associated with CVE-2005-0372?
CVE-2005-0372 is associated with a directory traversal attack that allows attackers to access arbitrary files on the server.
Is CVE-2005-0372 specific to certain operating systems?
CVE-2005-0372 primarily affects systems running the GTK+ version prior to 2.0.18, regardless of the operating system.