vulnerability

Huawei EulerOS: CVE-2017-17405: ruby security update

Severity
9
CVSS
(AV:N/AC:M/Au:N/C:C/I:C/A:C)
Published
Dec 15, 2017
Added
May 10, 2019
Modified
Aug 13, 2025

Description

It was discovered that the Net::FTP module did not properly process filenames in combination with certain operations. A remote attacker could exploit this flaw to execute arbitrary commands by setting up a malicious FTP server and tricking a user or Ruby application into downloading files with specially crafted names using the Net::FTP module.

Solutions

huawei-euleros-2_0_sp2-upgrade-rubyhuawei-euleros-2_0_sp2-upgrade-ruby-irbhuawei-euleros-2_0_sp2-upgrade-ruby-libs
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.