Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2008-4247
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2008-4247

Description:
ftpd in OpenBSD 4.3, FreeBSD 7.0, and NetBSD 4.0 interprets long commands from an FTP client as multiple commands, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and execute arbitrary FTP commands via a long ftp:// URI that leverages an existing session from the FTP client implementation in a web browser.

CVE Status:
Candidate

References:

ST
  1020946
  1021112

SREASONRES
  http://securityreason.com/achievement_securityalert/56

SREASON
  http://securityreason.com/securityalert/4313

SAID
  Secunia Advisory: SA32068
  Secunia Advisory: SA32070
  Secunia Advisory: SA33341

NETBSD

MISC
  http://bugs.proftpd.org/show_bug.cgi?id=3115

FREEBSD
  http://security.FreeBSD.org/advisories/FreeBSD-SA-08:12.ftpd.asc

CONFIRM
  http://www.openbsd.org/cgi-bin/cvsweb/src/libexec/ftpd/ftpd.c.diff?r1=1.183&r2=1.184&f=h
  http://www.openbsd.org/cgi-bin/cvsweb/src/libexec/ftpd/ftpd.c
  http://www.openbsd.org/cgi-bin/cvsweb/src/libexec/ftpd/ftpcmd.y.diff?r1=1.51&r2=1.52&f=h
  http://www.openbsd.org/cgi-bin/cvsweb/src/libexec/ftpd/ftpcmd.y


Return to the previous page.