Description
Directory traversal vulnerabilities in multiple FTP clients on UNIX systems allow remote malicious FTP servers to create or overwrite files as the client user via filenames containing /absolute/path or .. (dot dot) sequences.
References (6)
Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/6360
Patch, Third Party Advisory, US Government Resource third-party-advisory
x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/210409
Mailing List mailing-list
x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=103962838628940&w=2
Vendor Advisory vendor-advisory
x_refsource_sgi
ftp://patches.sgi.com/support/free/security/advisories/20021205-01-A
Third Party Advisory mailing-list
x_refsource_vulnwatch
http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0102.html
Third Party Advisory vdb-entry
x_refsource_xf
http://www.iss.net/security_center/static/10821.php
Scores
EPSS
0.0213
EPSS Percentile
84.4%
Details
Status
published
Products (15)
ncftp_software/ncftp
3.0.0
ncftp_software/ncftp
3.0.1
ncftp_software/ncftp
3.0.2
ncftp_software/ncftp
3.0.3
ncftp_software/ncftp
3.0.4
ncftp_software/ncftp
3.1.0
ncftp_software/ncftp
3.1.1
ncftp_software/ncftp
3.1.2
ncftp_software/ncftp
3.1.3
ncftp_software/ncftp
3.1.4
... and 5 more
Published
Dec 23, 2002
Tracked Since
Feb 18, 2026