This page displays vulnerability information about FreeBSD Ports.
The VUXML data was last processed by FreshPorts on 2024-11-27 06:34:59 UTC
List all Vulnerabilities, by package
List all Vulnerabilities, by date
k68These are the vulnerabilities relating to the commit you have selected:
VuXML ID | Description |
---|---|
29b7e3f4-b6a9-11df-ae63-f255a795cb21 | lftp -- multiple HTTP client download filename vulnerability The get1 command, as used by lftpget, in LFTP before 4.0.6 does not properly validate a server-provided filename before determining the destination filename of a download, which allows remote servers to create or overwrite arbitrary files via a Content-Disposition header that suggests a crafted filename, and possibly execute arbitrary code as a consequence of writing to a dotfile in a home directory. Discovery 2010-06-09 Entry 2010-09-03 lftp < 4.0.6 CVE-2010-2251 https://bugzilla.redhat.com/show_bug.cgi?id=591580 |