Family: Mandrake Local Security Checks --> Category: infos
MDKSA-2003:116: lftp Vulnerability Scan
Vulnerability Scan Summary
Check for the version of the lftp package
Detailed Explanation for this Vulnerability Test
The remote host is missing the patch for the advisory MDKSA-2003:116 (lftp).
A buffer overflow vulnerability was discovered by Ulf Harnhammar in the lftp FTP
client when connecting to a web server using HTTP or HTTPS and using the 'ls' or
'rels' command on specially prepared directory. This vulnerability exists in
lftp versions 2.3.0 through 2.6.9 and is corrected upstream in 2.6.10.
The updated packages are patched to protect against this problem.
Solution : http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2003:116
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.