Title : Redhat Security Update Fixes gftp Directory Traversal Vulnerability VUPEN ID : VUPEN/ADV-2005-0759 CVE ID : CVE-2005-0372 CWE ID : CWE-
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2005-06-14
Technical Description
Redhat has released a security patch to correct a vulnerability identified in gftp. This flaw is due to an input validation error when handling specially crafted "LIST" commands containing ".." (dot dot) sequences, which could be exploited to conduct directory traversal attacks.