CVE-2011-3171: Path Traversal
Directory traversal vulnerability in pure-FTPd 1.0.22 and possibly other versions, when running on SUSE Linux Enterprise Server and possibly other operating systems, when the Netware OES remote server feature is enabled, allows local users to overwrite arbitrary files via unknown vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-3171?
CVE-2011-3171 is considered a high-severity vulnerability due to its potential for local users to overwrite arbitrary files.
How do I fix CVE-2011-3171?
To fix CVE-2011-3171, update pure-FTPd to a version later than 1.0.22 that does not contain this vulnerability.
Which versions of pure-FTPd are affected by CVE-2011-3171?
CVE-2011-3171 affects pure-FTPd versions up to and including 1.0.22.
On which operating systems does CVE-2011-3171 occur?
CVE-2011-3171 occurs on SUSE Linux Enterprise Server and possibly other operating systems with the Netware OES remote server feature enabled.
Can local users exploit CVE-2011-3171?
Yes, local users can exploit CVE-2011-3171 to overwrite arbitrary files due to the directory traversal vulnerability.