CVE-2023-45198: High severity netbsd vulnerability
Published Oct 5, 2023
·Updated
ftpd before "NetBSD-ftpd 20230930" can leak information about the host filesystem before authentication via an MLSD or MLST command. tnftpd (the portable version of NetBSD ftpd) before 20231001 is also vulnerable.
Affected Software
2 affected components
NetBSD ftpd<2023-09-30
NetBSD tnftpd<2023-10-01
Remediation
Event History
Oct 5, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-45198.
2
What is the title of this vulnerability?
The title of this vulnerability is 'ftpd before NetBSD-ftpd 20230930 can leak information about the host filesystem before authentication'.
3
Which software is affected by this vulnerability?
The NetBSD ftpd before 'NetBSD-ftpd 20230930' and tnftpd before 20231001 are affected by this vulnerability.
4
What is the severity of CVE-2023-45198?
CVE-2023-45198 has a severity rating of 7.5 (high).
5
How can I fix this vulnerability?
To fix this vulnerability, update the affected software to a version that includes the security patch.