MEDIUM · 5.0

CVE-2002-1345

Directory traversal vulnerabilities in multiple FTP clients on UNIX systems allow remote malicious FTP servers to create or overwrite files as the client user via filenames containing /absolute/path o...

Vulnerability Description

Directory traversal vulnerabilities in multiple FTP clients on UNIX systems allow remote malicious FTP servers to create or overwrite files as the client user via filenames containing /absolute/path or .. (dot dot) sequences.

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:N/I:P/A:N
Confidentiality
NONE
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
Ncftp SoftwareNcftp3.0.0
OpenbsdOpenbsd3.0
SunSolaris2.6
SunSunos-

References

FAQ

What is CVE-2002-1345?

CVE-2002-1345 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Directory traversal vulnerabilities in multiple FTP clients on UNIX systems allow remote malicious FTP servers to create or overwrite files as the client user via filenames containing /absolute/path o...

How severe is CVE-2002-1345?

CVE-2002-1345 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2002-1345?

Check the references section above for vendor advisories and patch information. Affected products include: Ncftp Software Ncftp, Openbsd Openbsd, Sun Solaris, Sun Sunos.