First published: Fri Apr 27 2007(Updated: )
mirror --script in lftp before 3.5.9 does not properly quote shell metacharacters, which might allow remote user-assisted attackers to execute shell commands via a malicious script. NOTE: it is not clear whether this issue crosses security boundaries, since the script already supports commands such as "get" which could overwrite executable files.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
lftp | <=3.5.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-2348 is considered to be a moderate severity vulnerability as it allows remote user-assisted attackers to execute shell commands.
To fix CVE-2007-2348, update lftp to version 3.5.9 or later.
CVE-2007-2348 affects lftp versions prior to 3.5.9.
CVE-2007-2348 enables remote user-assisted code execution through improperly quoted shell metacharacters in scripts.
CVE-2007-2348 is not classified as critical, but it poses a risk if exploited by an attacker.