ftpd before "NetBSD-ftpd 20230930" can leak information about the host filesystem before authentication via an MLSD or MLST command. tnftpd (the portable version of NetBSD ftpd) before 20231001 is also vulnerable.
References
Link | Resource |
---|---|
http://cvsweb.netbsd.org/bsdweb.cgi/src/libexec/ftpd/ftpcmd.y.diff?r1=1.94&r2=1.95 | Patch |
https://mail-index.netbsd.org/source-changes/2023/09/22/msg147669.html | Mailing List Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2023-10-05T00:00:00
Updated: 2023-10-05T04:04:21.096906
Reserved: 2023-10-05T00:00:00
Link: CVE-2023-45198
JSON object: View
NVD Information
Status : Analyzed
Published: 2023-10-05T05:15:42.257
Modified: 2023-10-11T17:15:31.923
Link: CVE-2023-45198
JSON object: View
Redhat Information
No data.
CWE