MIT Kerberos Development Team Information for VU#258721
Various FTP clients fail to account for pipe (|) characters in default file names
- Vendor Information Help Date Notified: 17 Jan 2003
- Statement Date:
- Date Updated: 24 Jan 2003
Status
Affected
Vendor Statement
By inspection of the code, MIT krb5 releases up to and including krb5-1.2.7 appear to be vulnerable. Our development sources also appear to be vulnerable. We will be working on a patch.
Vendor Information
The vendor has not provided us with any further information regarding this vulnerability.
Vendor References
None
Addendum
The CERT/CC has no additional comments at this time.
If you have feedback, comments, or additional information about this vulnerability, please send us email.