Security restrictions bypass in vsftpd - CVE-2015-1419
Published: August 15, 2016 / Updated: November 20, 2018
Vulnerability details
The vulnerability allows a remote attacker to bypass certain security restrictions.
The vulnerability exists due to unknown error related to parsing of "deny_file" option. A remote authenticated attacker can bypass certain security restrictions and gain unauthorized access to protected files on the system.
Successful exploitation of the vulnerability may allow an authenticated attacker to bypass intended security restrictions.
Affected software
vsftpd (Alpine package)
cabextract (Alpine package)
How to mitigate CVE-2015-1419
cabextract (Alpine package) - update to 1.9.1-r0
- update to 2.11-8ubuntu4