First published: Mon Aug 06 2018(Updated: )
It was discovered that LFTP incorrectly handled certain files. An attacker could possibly use this issue to cause a denial of service.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/lftp | <4.8.1-1ubuntu0.1 | 4.8.1-1ubuntu0.1 |
Ubuntu OpenSSH Client | =18.04 | |
All of | ||
ubuntu/lftp | <4.6.3a-1ubuntu0.1 | 4.6.3a-1ubuntu0.1 |
Ubuntu OpenSSH Client | =16.04 | |
All of | ||
ubuntu/lftp | <4.4.13-1ubuntu0.1 | 4.4.13-1ubuntu0.1 |
Ubuntu OpenSSH Client | =14.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of USN-3731-1 is classified as high due to the potential for denial of service.
To fix USN-3731-1, you should upgrade the LFTP package to the recommended version depending on your Ubuntu release.
USN-3731-1 affects LFTP versions prior to 4.8.1-1ubuntu0.1 for Ubuntu 18.04, 4.6.3a-1ubuntu0.1 for Ubuntu 16.04, and 4.4.13-1ubuntu0.1 for Ubuntu 14.04.
USN-3731-1 is a denial of service vulnerability that can potentially disrupt service availability.
Users running affected versions of LFTP on Ubuntu 14.04, 16.04, or 18.04 are vulnerable to USN-3731-1.