Untrusted search path in FileZilla before 3.41.0-rc1 allows an attacker to gain privileges via a malicious 'fzsftp' binary in the user's home directory.
{ "binaries": [ { "binary_name": "filezilla", "binary_version": "3.15.0.2-1ubuntu1" }, { "binary_name": "filezilla-common", "binary_version": "3.15.0.2-1ubuntu1" } ] }
{ "binaries": [ { "binary_name": "filezilla", "binary_version": "3.28.0-1" }, { "binary_name": "filezilla-common", "binary_version": "3.28.0-1" } ] }