First published: Fri Nov 04 2011(Updated: )
Directory traversal vulnerability in pure-FTPd 1.0.22 and possibly other versions, when running on SUSE Linux Enterprise Server and possibly other operating systems, when the Netware OES remote server feature is enabled, allows local users to overwrite arbitrary files via unknown vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Pure-FTPd | <=1.0.22 | |
Pure-FTPd | =0.90 | |
Pure-FTPd | =0.91 | |
Pure-FTPd | =0.92 | |
Pure-FTPd | =0.93 | |
Pure-FTPd | =0.94 | |
Pure-FTPd | =0.95 | |
Pure-FTPd | =0.95-pre1 | |
Pure-FTPd | =0.95-pre2 | |
Pure-FTPd | =0.95-pre3 | |
Pure-FTPd | =0.95-pre4 | |
Pure-FTPd | =0.95.1 | |
Pure-FTPd | =0.95.2 | |
Pure-FTPd | =0.96 | |
Pure-FTPd | =0.96-pre1 | |
Pure-FTPd | =0.96.1 | |
Pure-FTPd | =0.97-pre1 | |
Pure-FTPd | =0.97-pre2 | |
Pure-FTPd | =0.97-pre3 | |
Pure-FTPd | =0.97-pre4 | |
Pure-FTPd | =0.97-pre5 | |
Pure-FTPd | =0.97-final | |
Pure-FTPd | =0.97.1 | |
Pure-FTPd | =0.97.2 | |
Pure-FTPd | =0.97.3 | |
Pure-FTPd | =0.97.4 | |
Pure-FTPd | =0.97.5 | |
Pure-FTPd | =0.97.6 | |
Pure-FTPd | =0.97.7 | |
Pure-FTPd | =0.97.7-pre1 | |
Pure-FTPd | =0.97.7-pre2 | |
Pure-FTPd | =0.97.7-pre3 | |
Pure-FTPd | =0.98-final | |
Pure-FTPd | =0.98-pre1 | |
Pure-FTPd | =0.98-pre2 | |
Pure-FTPd | =0.98.1 | |
Pure-FTPd | =0.98.2 | |
Pure-FTPd | =0.98.2-a | |
Pure-FTPd | =0.98.3 | |
Pure-FTPd | =0.98.4 | |
Pure-FTPd | =0.98.5 | |
Pure-FTPd | =0.98.6 | |
Pure-FTPd | =0.98.7 | |
Pure-FTPd | =0.99 | |
Pure-FTPd | =0.99-a | |
Pure-FTPd | =0.99-b | |
Pure-FTPd | =0.99-pre1 | |
Pure-FTPd | =0.99-pre2 | |
Pure-FTPd | =0.99.1 | |
Pure-FTPd | =0.99.1-a | |
Pure-FTPd | =0.99.1-b | |
Pure-FTPd | =0.99.2 | |
Pure-FTPd | =0.99.2-a | |
Pure-FTPd | =0.99.3 | |
Pure-FTPd | =0.99.4 | |
Pure-FTPd | =0.99.9 | |
Pure-FTPd | =1.0.0 | |
Pure-FTPd | =1.0.1 | |
Pure-FTPd | =1.0.2 | |
Pure-FTPd | =1.0.3 | |
Pure-FTPd | =1.0.4 | |
Pure-FTPd | =1.0.5 | |
Pure-FTPd | =1.0.6 | |
Pure-FTPd | =1.0.7 | |
Pure-FTPd | =1.0.8 | |
Pure-FTPd | =1.0.9 | |
Pure-FTPd | =1.0.10 | |
Pure-FTPd | =1.0.11 | |
Pure-FTPd | =1.0.12 | |
Pure-FTPd | =1.0.13-a | |
Pure-FTPd | =1.0.14 | |
Pure-FTPd | =1.0.15 | |
Pure-FTPd | =1.0.16-a | |
Pure-FTPd | =1.0.16-b | |
Pure-FTPd | =1.0.16-c | |
Pure-FTPd | =1.0.17 | |
Pure-FTPd | =1.0.17-a | |
Pure-FTPd | =1.0.18 | |
Pure-FTPd | =1.0.19 | |
Pure-FTPd | =1.0.20 | |
Pure-FTPd | =1.0.21 | |
SUSE Linux Enterprise Desktop with Beagle | =10-sp4 | |
SUSE Linux Enterprise Desktop with Beagle | =11-sp1 | |
SUSE Linux Enterprise Server | =10-sp3 | |
SUSE Linux Enterprise Server | =10-sp4 | |
SUSE Linux Enterprise Server | =11-sp1 | |
SUSE Linux Enterprise Server | =11-sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-3171 is considered a high-severity vulnerability due to its potential for local users to overwrite arbitrary files.
To fix CVE-2011-3171, update pure-FTPd to a version later than 1.0.22 that does not contain this vulnerability.
CVE-2011-3171 affects pure-FTPd versions up to and including 1.0.22.
CVE-2011-3171 occurs on SUSE Linux Enterprise Server and possibly other operating systems with the Netware OES remote server feature enabled.
Yes, local users can exploit CVE-2011-3171 to overwrite arbitrary files due to the directory traversal vulnerability.