|
|
|
View Notes By
|
|
|
|
Other Documents
|
|
|
|
|
Sun Microsystems Inc. Information for VU#210409
| Date Notified | 12/05/2002 |
| Date Modified | 03/14/2003 03:50:33 PM |
| Status Summary | Vulnerable |
Vendor StatementWe have investigated this directory traversal issue and do not think it is a bug.
The user has several means of protection against this issue.
1. By default prompting is turned on, so the user gets a chance to decide if they want a file returned by mget before it is downloaded. So files will not be overwritten without prompting the user.
2. When running as an ordinary user, Unix access controls will stop system files being over written. If a user must run as root, care needs to be taken which would include not turning off interactive mode.
3. The user may run the "runique" command to force the Solaris ftp client to avoid overwriting files that already exist.
The Solaris ftp mget behaviour is consistent with other BSD derived ftp clients, for example on Linux and FreeBSD. Changing the existing behaviour will cause problems.US-CERT AddendumThe CERT/CC has no additional comments at this time.
If you have feedback, comments, or additional information about this vulnerability, please send us
email.
|
 |