CVE-2023-24042: Path Traversal
Published Jan 21, 2023
·Updated
A race condition in LightFTP through 2.2 allows an attacker to achieve path traversal via a malformed FTP request. A handler thread can use an overwritten context->FileName.
Affected Software
2 affected components
Lightftp Project Lightftp<=2.2
Hfiref0x Lightftp<=2.2
Event History
Jan 21, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-24042?
CVE-2023-24042 has a medium severity rating due to its potential for path traversal attacks.
2
How do I fix CVE-2023-24042?
To fix CVE-2023-24042, update LightFTP to version 2.3 or later, which addresses the vulnerability.
3
Who is affected by CVE-2023-24042?
CVE-2023-24042 affects users of LightFTP versions up to and including 2.2 from both the LightFTP project and Hfiref0x.
4
What type of vulnerability is CVE-2023-24042?
CVE-2023-24042 is a race condition that allows for path traversal via malformed FTP requests.
5
What are the implications of CVE-2023-24042?
If exploited, CVE-2023-24042 can allow an attacker to access unauthorized files on the server.