CVE-2007-2348

Source
https://nvd.nist.gov/vuln/detail/CVE-2007-2348
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2007-2348.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2007-2348
Published
2007-04-27T18:19:00Z
Modified
2024-11-21T00:30:34Z
Summary
[none]
Details

mirror --script in lftp before 3.5.9 does not properly quote shell metacharacters, which might allow remote user-assisted attackers to execute shell commands via a malicious script. NOTE: it is not clear whether this issue crosses security boundaries, since the script already supports commands such as "get" which could overwrite executable files.

References

Affected packages

Debian:11 / lftp

Package

Name
lftp
Purl
pkg:deb/debian/lftp?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.5.9-1

Ecosystem specific

{
    "urgency": "unimportant"
}

Debian:12 / lftp

Package

Name
lftp
Purl
pkg:deb/debian/lftp?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.5.9-1

Ecosystem specific

{
    "urgency": "unimportant"
}

Debian:13 / lftp

Package

Name
lftp
Purl
pkg:deb/debian/lftp?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.5.9-1

Ecosystem specific

{
    "urgency": "unimportant"
}