CVE-2009-5012: Medium severity pyftpdlib vulnerability
Published Oct 19, 2010
·Updated
ftpserver.py in pyftpdlib before 0.5.2 does not require the l permission for the MLST command, which allows remote authenticated users to bypass intended access restrictions and list the root directory via an FTP session.
Affected Software
8 affected componentsFixes available
pip/pyftpdlib<=0.5.1
0.5.2
G.rodola Pyftpdlib<=0.5.1
G.rodola Pyftpdlib=0.1
G.rodola Pyftpdlib=0.1.1
G.rodola Pyftpdlib=0.2.0
G.rodola Pyftpdlib=0.3.0
G.rodola Pyftpdlib=0.4.0
G.rodola Pyftpdlib=0.5.0
Event History
Oct 19, 2010
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
May 2, 2022
Advisory Published
via GitHub·04:00 AM
Frequently Asked Questions
1
What is the severity of CVE-2009-5012?
CVE-2009-5012 is classified as a medium severity vulnerability.
2
How do I fix CVE-2009-5012?
To fix CVE-2009-5012, upgrade pyftpdlib to version 0.5.2 or later.
3
What is the exploit mechanism of CVE-2009-5012?
CVE-2009-5012 allows remote authenticated users to bypass access restrictions and list the root directory via the MLST command.
4
Which versions of pyftpdlib are affected by CVE-2009-5012?
Versions of pyftpdlib prior to 0.5.2, including all versions from 0.1.0 to 0.5.1, are affected by CVE-2009-5012.
5
Who is impacted by CVE-2009-5012?
Remote authenticated users of affected pyftpdlib versions are impacted by CVE-2009-5012 due to the lack of permission checks.