First published: Fri Mar 16 2007(Updated: )
** DISPUTED ** Buffer overflow in the set_umask function in QFTP in LIBFtp 3.1-1 allows local users to execute arbitrary code via a long -m argument. NOTE: CVE disputes this issue because QFTP is not setuid, and it is unlikely that there are web interfaces to QFTP that would accept untrusted command line arguments.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Plib | =3.1-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2007-1485 is disputed due to the lack of a setuid context for the vulnerable QFTP application.
To fix CVE-2007-1485, upgrade to a patched version of LIBFtp that addresses the buffer overflow issue.
CVE-2007-1485 affects local users running LIBFtp version 3.1-1 using the QFTP component.
CVE-2007-1485 is a buffer overflow vulnerability in the set_umask function.
CVE-2007-1485 is unlikely to be exploited remotely, as it requires local access and execution of the QFTP application.