漏洞信息详情
glftpd privpath指令漏洞
- CNNVD编号:CNNVD-200006-101
- 危害等级: 超危
- CVE编号:
CVE-2000-0587
- 漏洞类型:
访问验证错误
- 发布时间:
2000-06-26
- 威胁类型:
远程
- 更新时间:
2005-07-27
- 厂 商:
glftpd - 漏洞来源:
This vulnerability… -
漏洞简介
glftpd 1.18版本中privpath指令存在漏洞。远程攻击者通过使用名称补全功能可以绕过目录的访问控制。
漏洞公告
This vulnerability was fixed in version 1.21 of glftpd, avilable at glftpd.deepwell.com
A program to work around this vulnerability is below.
GlFtpd GlFtpd 1.18
-
glFtpD glFtpD 1.21
http://www.glftpd.org
GlFtpd GlFtpd 1.19
-
glFtpD glFtpD 1.21
http://www.glftpd.org
GlFtpd GlFtpd 1.20
-
glFtpD glFtpD 1.21
http://www.glftpd.org -
Hoopy
leakfix.c @risciso.com>
http://www.securityfocus.com/data/vulnerabilities/patches/leakfix.c
GlFtpd GlFtpd 1.21 b4
-
glFtpD glFtpD 1.21
http://www.glftpd.org -
Hoopy
leakfix.c @risciso.com>
http://www.securityfocus.com/data/vulnerabilities/patches/leakfix.c
GlFtpd GlFtpd 1.21 b1
-
glFtpD glFtpD 1.21
http://www.glftpd.org -
Hoopy
leakfix.c @risciso.com>
http://www.securityfocus.com/data/vulnerabilities/patches/leakfix.c
GlFtpd GlFtpd 1.21 b6
-
glFtpD glFtpD 1.21
http://www.glftpd.org -
Hoopy
leakfix.c @risciso.com>
http://www.securityfocus.com/data/vulnerabilities/patches/leakfix.c
GlFtpd GlFtpd 1.21 b2
-
glFtpD glFtpD 1.21
http://www.glftpd.org -
Hoopy
leakfix.c @risciso.com>
http://www.securityfocus.com/data/vulnerabilities/patches/leakfix.c
GlFtpd GlFtpd 1.21 b5
-
glFtpD glFtpD 1.21
http://www.glftpd.org -
Hoopy
leakfix.c @risciso.com>
http://www.securityfocus.com/data/vulnerabilities/patches/leakfix.c
GlFtpd GlFtpd 1.21 b8
-
glFtpD glFtpD 1.21
http://www.glftpd.org -
Hoopy
leakfix.c @risciso.com>
http://www.securityfocus.com/data/vulnerabilities/patches/leakfix.c
GlFtpd GlFtpd 1.21 b3
-
glFtpD glFtpD 1.21
http://www.glftpd.org -
Hoopy
leakfix.c @risciso.com>
http://www.securityfocus.com/data/vulnerabilities/patches/leakfix.c
GlFtpd GlFtpd 1.21 b7
-
glFtpD glFtpD 1.21
http://www.glftpd.org -
Hoopy
leakfix.c @risciso.com>
http://www.securityfocus.com/data/vulnerabilities/patches/leakfix.c
参考网址
来源: BUGTRAQ
名称: 20000626 Glftpd privpath bugs… +fix
链接:http://www.securityfocus.com/templates/archive.pike?list=1&msg=Pine.LNX.4.10.10006261041360.31907-200000@twix.thrijswijk.nl
来源: BID
名称: 1401
链接:http://www.securityfocus.com/bid/1401
来源: BUGTRAQ
名称: 20000627 Re: Glftpd privpath bugs… +fix
链接:http://archives.neohapsis.com/archives/bugtraq/2000-06/0317.html