Untrusted search path in FileZilla before 3.41.0-rc1 allows an attacker to gain privileges via a malicious 'fzsftp' binary in the user's home directory.
{ "availability": "No subscription required", "ubuntu_priority": "low", "binaries": [ { "binary_version": "3.45.1-3", "binary_name": "filezilla" }, { "binary_version": "3.45.1-3", "binary_name": "filezilla-common" }, { "binary_version": "3.45.1-3", "binary_name": "filezilla-dbgsym" } ] }