漏洞信息详情
ArGoSoft FTP服务器快捷方式文件上传漏洞
- CNNVD编号:CNNVD-200502-066
- 危害等级: 超危
- CVE编号:
CVE-2005-0519
- 漏洞类型:
输入验证
- 发布时间:
2005-02-18
- 威胁类型:
远程
- 更新时间:
2007-01-24
- 厂 商:
argosoft - 漏洞来源:
ArGoSoft -
漏洞简介
ArGoSoft FTP是一个免费的Windows95/98/NT的FTP服务器,。
ArGoSoft FTP Server 1.4.2.7之前的版本可让远程攻击者通过上传包含快捷方式(.LNK)文件的ZIP文件,再使用SITE UNZIP将.LNK文件解压缩到服务器上,然后访问该文件来读取任意文件。
漏洞公告
目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:
ArGoSoft FTP Server 1.0
ArGoSoft FTP Server 1.4.2.2
http://www.argosoft.com/dl/default.aspx?filename=fssetup.exe
ArGoSoft FTP Server 1.2.2 .2
ArGoSoft FTP Server 1.4.2.2
http://www.argosoft.com/dl/default.aspx?filename=fssetup.exe
ArGoSoft FTP Server 1.4.1 .4
ArGoSoft FTP Server 1.4.2.2
http://www.argosoft.com/dl/default.aspx?filename=fssetup.exe
ArGoSoft FTP Server 1.4.1 .2
ArGoSoft FTP Server 1.4.2.2
http://www.argosoft.com/dl/default.aspx?filename=fssetup.exe
ArGoSoft FTP Server 1.4.1 .8
ArGoSoft FTP Server 1.4.2.2
http://www.argosoft.com/dl/default.aspx?filename=fssetup.exe
ArGoSoft FTP Server 1.4.1 .5
ArGoSoft FTP Server 1.4.2.2
http://www.argosoft.com/dl/default.aspx?filename=fssetup.exe
ArGoSoft FTP Server 1.4.1 .9
ArGoSoft FTP Server 1.4.2.2
http://www.argosoft.com/dl/default.aspx?filename=fssetup.exe
ArGoSoft FTP Server 1.4.1 .6
ArGoSoft FTP Server 1.4.2.2
http://www.argosoft.com/dl/default.aspx?filename=fssetup.exe
ArGoSoft FTP Server 1.4.1 .3
ArGoSoft FTP Server 1.4.2.2
http://www.argosoft.com/dl/default.aspx?filename=fssetup.exe
ArGoSoft FTP Server 1.4.1 .1
ArGoSoft FTP Server 1.4.2.2
http://www.argosoft.com/dl/default.aspx?filename=fssetup.exe
ArGoSoft FTP Server 1.4.1 .7
ArGoSoft FTP Server 1.4.2.2
http://www.argosoft.com/dl/default.aspx?filename=fssetup.exe
ArGoSoft FTP Server 1.4.2 .1
ArGoSoft FTP Server 1.4.2.2
http://www.argosoft.com/dl/default.aspx?filename=fssetup.exe
ArGoSoft FTP Server 1.4.2 .0
ArGoSoft FTP Server 1.4.2.2
http://www.argosoft.com/dl/default.aspx?filename=fssetup.exe
参考网址
来源: www.argosoft.com
链接:http://www.argosoft.com/ftpserver/changelist.aspx
来源: SECUNIA
名称: 14172
链接:http://secunia.com/advisories/14172
来源: XF
名称: argosoft-ink-file-upload(17939)
链接:http://xforce.iss.net/xforce/xfdb/17939
来源: BID
名称: 12487
链接:http://www.securityfocus.com/bid/12487
来源: OSVDB
名称: 13614