First published: Thu Oct 05 2023(Updated: )
ftpd before "NetBSD-ftpd 20230930" can leak information about the host filesystem before authentication via an MLSD or MLST command. tnftpd (the portable version of NetBSD ftpd) before 20231001 is also vulnerable.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
NetBSD ftpd | <2023-09-30 | |
Netbsd Tnftpd | <2023-10-01 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2023-45198.
The title of this vulnerability is 'ftpd before NetBSD-ftpd 20230930 can leak information about the host filesystem before authentication'.
The NetBSD ftpd before 'NetBSD-ftpd 20230930' and tnftpd before 20231001 are affected by this vulnerability.
CVE-2023-45198 has a severity rating of 7.5 (high).
To fix this vulnerability, update the affected software to a version that includes the security patch.