Vulnerability Description
ftpd before "NetBSD-ftpd 20230930" can leak information about the host filesystem before authentication via an MLSD or MLST command. tnftpd (the portable version of NetBSD ftpd) before 20231001 is also vulnerable.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Netbsd | Ftpd | < 2023-09-30 |
| Netbsd | Tnftpd | < 2023-10-01 |
References
- http://cvsweb.netbsd.org/bsdweb.cgi/src/libexec/ftpd/ftpcmd.y.diff?r1=1.94&r2=1.Patch
- https://mail-index.netbsd.org/source-changes/2023/09/22/msg147669.htmlMailing ListVendor Advisory
- http://cvsweb.netbsd.org/bsdweb.cgi/src/libexec/ftpd/ftpcmd.y.diff?r1=1.94&r2=1.Patch
- https://mail-index.netbsd.org/source-changes/2023/09/22/msg147669.htmlMailing ListVendor Advisory
FAQ
What is CVE-2023-45198?
CVE-2023-45198 is a vulnerability with a CVSS score of 7.5 (HIGH). ftpd before "NetBSD-ftpd 20230930" can leak information about the host filesystem before authentication via an MLSD or MLST command. tnftpd (the portable version of NetBSD ftpd) before 20231001 is als...
How severe is CVE-2023-45198?
CVE-2023-45198 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-45198?
Check the references section above for vendor advisories and patch information. Affected products include: Netbsd Ftpd, Netbsd Tnftpd.