Buffer overflow in the set_umask function in QFTP in LIBFtp 3.1-1 allows local users to execute arbitrary code via a long -m argument. NOTE: CVE disputes this issue because QFTP is not setuid, and it is unlikely that there are web interfaces to QFTP that would accept untrusted command line arguments
Link | Tags |
---|---|
http://www.securityfocus.com/archive/1/462952/100/0/threaded | mailing list |
http://www.securityfocus.com/bid/22986 | vdb entry |
http://securityreason.com/securityalert/2443 | third party advisory |
http://osvdb.org/35089 | vdb entry |