MIT Kerberos Development Team Information for VU#258721

Various FTP clients fail to account for pipe (|) characters in default file names



Vendor Statement

By inspection of the code, MIT krb5 releases up to and including krb5-1.2.7 appear to be vulnerable. Our development sources also appear to be vulnerable. We will be working on a patch.

