CVE-2018-10916 MEDIUM

CVE-2018-10916

Vendor [Unknown]
Product lftp
Weakness CWE-20 · Input validation
Published August 1, 2018
Last update August 5, 2024

CVSS base score

5.3/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction Required
Confidentiality None
Integrity High

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N

What the vulnerability does

01Description

It has been discovered that lftp up to and including version 4.8.3 does not properly sanitize remote file names, leading to a loss of integrity on the local system when reverse mirroring is used. A remote attacker may trick a user to use reverse mirroring on an attacker controlled FTP server, resulting in the removal of all files in the current working directory of the victim's system.

Key dates

02Disclosure timeline

August 1, 2018 CVE published
August 5, 2024 Record updated