Oval Definition:oval:com.redhat.rhsa:def:20201045
Revision Date:2020-03-31Version:638
Title:RHSA-2020:1045: lftp security update (Moderate)
Description:LFTP is a file transfer utility for File Transfer Protocol (FTP), Secure File Transfer Protocol (SFTP), Hypertext Transfer Protocol (HTTP), and other commonly used protocols. It uses the readline library for input, and provides support for bookmarks, built-in monitoring, job control, and parallel transfer of multiple files at the same time.

Security Fix(es):

  • lftp: particular remote file names may lead to current working directory erased (CVE-2018-10916)

    For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

    Additional Changes:

    For detailed information on changes in this release, see the Red Hat Enterprise Linux 7.8 Release Notes linked from the References section.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2018-10916
    RHSA-2020:1045
    Platform(s):Red Hat Enterprise Linux 7
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 7 is installed
  • AND
  • lftp is earlier than 0:4.4.8-12.el7
  • AND lftp is signed with Red Hat redhatrelease2 key
  • lftp-scripts is earlier than 0:4.4.8-12.el7
  • AND lftp-scripts is signed with Red Hat redhatrelease2 key
  • BACK