LFTP is a sophisticated file transfer program for the FTP and HTTPprotocols. Like Bash, it has job control and uses the Readline library forinput. It has bookmarks, built-in mirroring, and can transfer several filesin parallel. It is designed with reliability in mind.It was discovered that lftp trusted the file name provided in theContent-Disposition HTTP header. A malicious HTTP server could use thisflaw to write or overwrite files in the current working directory of avictim running lftp, by sending a different file from what the victimrequested. (CVE-2010-2251)To correct this flaw, the following changes were made to lftp: the"xfer:clobber" option now defaults to "no", causing lftp to not overwriteexisting files, and a new option, "xfer:auto-rename", which defaults to"no", has been introduced to control whether lftp should useserver-suggested file names. Refer to the "Settings" section of the lftp(1)manual page for additional details on changing lftp settings.All lftp users should upgrade to this updated package, which contains abackported patch to correct this issue.