Google Site SearchFN Site Search FN Blog Login FN Blog Login
Site Navigation:
 
 

Fedora Update

This update can be downloaded from:
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/
This update can be installed with Yum Update Agent; you can type 'yum update' command in the terminal.
This update can also be installed with the Red Hat Update Agent; you can launch the Red Hat Update Agent with the 'up2date' command in the terminal.

[SECURITY] Fedora Core 1 Update: lftp-2.6.10-1

---------------------------------------------------------------------
Fedora Update Notification
FEDORA-2003-034
2003-12-15
---------------------------------------------------------------------

Name        : lftp
Version     : 2.6.10                      
Release     : 1                  
Summary     : A sophisticated file transfer program
Description :
LFTP is a sophisticated ftp/http file transfer program. Like bash, it
has job control and uses the readline library for input. It has
bookmarks, built-in mirroring, and can transfer several files in
parallel. It is designed with reliability in mind.

---------------------------------------------------------------------

Update Information:

Ulf Härnhammar found a remotely-triggerable buffer overflow in lftp.

An attacker could create a carefully crafted directory on a website
such that, if a user connects to that directory using the lftp client
and subsequently issues a 'ls' or 'rels' command, the attacker could
execute arbitrary code on the users machine. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2003-0963 to this issue.

Users of lftp are advised to upgrade to these erratum packages, which
upgrade lftp to a version which is not vulnerable to this issue.

Red Hat would like to thank Ulf Härnhammar for discovering and
alerting us to this issue.

---------------------------------------------------------------------