ID | CVE-2014-8517 | ||||||
Sažetak | The fetch_url function in usr.bin/ftp/fetch.c in tnftp, as used in NetBSD 5.1 through 5.1.4, 5.2 through 5.2.2, 6.0 through 6.0.6, and 6.1 through 6.1.5 allows remote attackers to execute arbitrary commands via a | (pipe) character at the end of an HTTP redirect. | ||||||
Reference |
|
||||||
CVSS |
|
||||||
Pristup |
|
||||||
Impact |
|
||||||
CVSS vektor | AV:N/AC:L/Au:N/C:P/I:P/A:P | ||||||
Zadnje važnije ažuriranje | 06-11-2017 - 02:29 | ||||||
Objavljeno | 17-11-2014 - 16:59 |