wu-ftp with FTP conversion enabled allows an attacker to execute commands via a malformed file name that is interpreted as an argument to the program that does the conversion, e.g. tar or uncompress.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2000-04-25T04:00:00

Updated: 2004-09-02T09:00:00

Reserved: 1999-12-21T00:00:00


Link: CVE-1999-0997

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 1999-12-20T05:00:00.000

Modified: 2008-09-05T20:18:28.777


Link: CVE-1999-0997

JSON object: View

cve-icon Redhat Information

No data.