The fetch_url function in usr.bin/ftp/fetch.c in tnftp, as used in NetBSD 5.1 through 5.1.4, 5.2 through 5.2.2, 6.0 through 6.0.6, and 6.1 through 6.1.5 allows remote attackers to execute arbitrary commands via a | (pipe) character at the end of an HTTP redirect.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Afpserver | — | Apply Apple macOS Security Update 2015-001 | Aug 28, 2015 | Nov 17, 2014 |
| Apple Osx Lukemftp | — | Apply Apple macOS Security Update 2015-001Upgrade macOS to the latest version | Mar 29, 2016 | Nov 17, 2014 |
| Debian | — | Upgrade tnftp | Jul 30, 2024 | Nov 17, 2014 |
| Freebsd | — | Upgrade FreeBSD | Dec 10, 2025 | Aug 11, 2016 |
| Gentoo Linux | — | Upgrade net-ftp/tnftp. | Oct 30, 2017 | Nov 17, 2014 |
| Suse | — | Upgrade tnftp | Dec 18, 2015 | Nov 10, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub