First published: Fri Aug 21 2009(Updated: )
tnftpd before 20080929 splits large command strings into multiple commands, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks via unknown vectors, probably involving a crafted ftp:// link to a tnftpd server.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Luke Mewburn TNFtpd | =20040810 | |
Luke Mewburn TNFtpd | =20061217 | |
Luke Mewburn TNFtpd | =20080609 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-7016 is classified as a medium severity vulnerability due to its potential for cross-site request forgery (CSRF) attacks.
To mitigate CVE-2008-7016, upgrade to a version of tnftpd released after 20080929 that does not have this vulnerability.
CVE-2008-7016 affects tnftpd versions 20040810, 20061217, and 20080609.
CVE-2008-7016 is associated with cross-site request forgery (CSRF) attacks.
While specific instances of CVE-2008-7016 may no longer be prevalent, any vulnerable systems that haven’t been updated remain a risk.