The get1 command, as used by lftpget, in LFTP before 4.0.6 does not properly validate a server-provided filename before determining the destination filename of a download, which allows remote servers to create or overwrite arbitrary files via a Content-Disposition header that suggests a crafted filename, and possibly execute arbitrary code as a consequence of writing to a dotfile in a home directory.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade lftp | Dec 1, 2016 | Jul 6, 2010 |
| Debian | — | Upgrade lftp | Jul 30, 2024 | Jul 6, 2010 |
| Freebsd | — | Upgrade lftp | Dec 10, 2025 | Sep 3, 2010 |
| Gentoo Linux | — | Upgrade dev-util/insight.Upgrade app-text/dvipng.Upgrade kde-base/kdm.Upgrade media-tv/dvbstreamer.Upgrade x11-apps/xinit.Upgrade sys-apps/pmount.Upgrade net-mail/mlmmj.Upgrade x11-misc/slim.Upgrade app-arch/gzip.Upgrade app-text/gv.Upgrade sys-apps/acl.Upgrade dev-perl/perl-tk.Upgrade sys-auth/pam_krb5.Upgrade kde-base/kget.Upgrade x11-libs/gtk+.Upgrade net-ftp/lftp.Upgrade sys-devel/m4.Upgrade media-gfx/splashutils.Upgrade app-antivirus/bitdefender-console.Upgrade dev-lang/tk.Upgrade www-client/uzbl.Upgrade app-misc/beanstalkd.Upgrade app-arch/ncompress.Upgrade dev-util/sourcenav.Upgrade sys-block/partimage.Upgrade dev-libs/liblzw.Upgrade net-misc/iputils. | Oct 30, 2017 | Jul 6, 2010 |
| Oracle_linux | — | Upgrade lftp | Oct 16, 2024 | Jul 6, 2010 |
| Suse | — | Upgrade lftp | Feb 17, 2015 | Jul 6, 2010 |
| Ubuntu | — | Upgrade lftp | Nov 8, 2024 | Jul 6, 2010 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub