CVE-2004-1294
EPSS 1.00%
Description
The mget function in cmds.c for tnftp 20030825 allows remote FTP servers to overwrite arbitrary files via FTP responses containing file names with / (slash) characters.
How to fix CVE-2004-1294
To remediate CVE-2004-1294, upgrade the affected package to a fixed version below.
- Debian/tnftp—upgrade to 20050625-0.1 or later
Is CVE-2004-1294 being exploited?
Low — EPSS is 1.0%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 20050625-0.1