Directory traversal vulnerabilities in multiple FTP clients on UNIX systems allow remote malicious FTP servers to create or overwrite files as the client user via filenames containing /absolute/path or .. (dot dot) sequences.
| Software | From | Fixed in |
|---|---|---|
| ncftp_software / ncftp | 3.0.2 | 3.0.2.x |
| ncftp_software / ncftp | 3.1.3 | 3.1.3.x |
| ncftp_software / ncftp | 3.1.4 | 3.1.4.x |
| ncftp_software / ncftp | 3.0.0 | 3.0.0.x |
| ncftp_software / ncftp | 3.1.0 | 3.1.0.x |
| ncftp_software / ncftp | 3.0.3 | 3.0.3.x |
| ncftp_software / ncftp | 3.1.1 | 3.1.1.x |
| ncftp_software / ncftp | 3.0.1 | 3.0.1.x |
| ncftp_software / ncftp | 3.1.2 | 3.1.2.x |
| ncftp_software / ncftp | 3.0.4 | 3.0.4.x |
| sun / sunos | 5.7 | 5.7.x |
| sun / solaris | 7.0 | 7.0.x |
| openbsd / openbsd | 3.0 | 3.0.x |
| sun / solaris | 2.6 | 2.6.x |