CVE-2014-8517
EPSS 69.1%
描述
The fetch_url function in usr.bin/ftp/fetch.c in tnftp, as used in NetBSD 5.1 through 5.1.4, 5.2 through 5.2.2, 6.0 through 6.0.6, and 6.1 through 6.1.5 allows remote attackers to execute arbitrary commands via a | (pipe) character at the end of an HTTP redirect.
如何修補 CVE-2014-8517
要修補 CVE-2014-8517,請將受影響套件升級到下列已修補版本。
- Debian/tnftp—升級至 20130505-2 或更新版本
CVE-2014-8517 正在被利用嗎?
可能 — EPSS 為 69.1%,屬於高被利用機率區間,建議優先修補。
受影響套件(1)
- from 0, < 20130505-2