CVE-2004-1294
EPSS 1.00%
描述
The mget function in cmds.c for tnftp 20030825 allows remote FTP servers to overwrite arbitrary files via FTP responses containing file names with / (slash) characters.
如何修補 CVE-2004-1294
要修補 CVE-2004-1294,請將受影響套件升級到下列已修補版本。
- Debian/tnftp—升級至 20050625-0.1 或更新版本
CVE-2004-1294 正在被利用嗎?
低 — EPSS 為 1.0%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- Debian/tnftpfrom 0, < 20050625-0.1