Trend Micro Security

Core FTP 'LIST' Command Directory Traversal Vulnerability

  危険度: :
  CVE識別番号: CVE-2008-2519

  概要

Core FTP is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input data. Exploiting this issue allows an attacker to write arbitrary files to locations outside of the FTP client's current directory. This could help the attacker launch further attacks.

  トレンドマイクロの対策

Apply associated Trend Micro DPI Rules.

  対応方法

  Trend Micro Deep Security DPI Rule Number: 1003788
  Trend Micro Deep Security DPI Rule Name: 1003788 - Core FTP 'LIST' Command Directory Traversal Vulnerability

  影響を受けるソフトウェア

  • Core FTP
  • Core FTP client 2.1 Build 1565