« Back to list

CVE-2007-2348

Status: ModifiedMedium (6.8)—

mirror --script in lftp before 3.5.9 does not properly quote shell metacharacters, which might allow remote user-assisted attackers to execute shell commands via a malicious script. NOTE: it is not clear whether this issue crosses security boundaries, since the script already supports commands such as "get" which could overwrite executable files.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (1)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2007-2348",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": true,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2007-04-27T18:19:00.000",
  "references": [
    {
      "url": "http://bugs.gentoo.org/show_bug.cgi?id=173524",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://lftp.yar.ru/news.html",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://rhn.redhat.com/errata/RHSA-2009-1278.html",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://secunia.com/advisories/25107",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://secunia.com/advisories/25132",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://secunia.com/advisories/36559",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/23736",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2007/1590",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://issues.rpath.com/browse/RPL-1229",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10806",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://bugs.gentoo.org/show_bug.cgi?id=173524",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://lftp.yar.ru/news.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://rhn.redhat.com/errata/RHSA-2009-1278.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/25107",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/25132",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/36559",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/23736",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2007/1590",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://issues.rpath.com/browse/RPL-1229",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10806",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "mirror --script in lftp before 3.5.9 does not properly quote shell metacharacters, which might allow remote user-assisted attackers to execute shell commands via a malicious script.  NOTE: it is not clear whether this issue crosses security boundaries, since the script already supports commands such as \"get\" which could overwrite executable files."
    },
    {
      "lang": "es",
      "value": "La secuencia de comandos mirror en lftp anterior a 3.5.9 no cita adecaudamente el interprete de carácteres metacaracter, lo cual podría permitir atacantes con la intervención del usuario ejecutar comandos del interprete de comandos (shell) a través de secuencias de comandos maliciosas. NOTA: no está claro si este asunto cruza los límites de la seguridad, puesto que que la secuencia de comandos apoya  comandos como por ejemplo “get” que podrían sobreescribir ficheros ejecutables."
    }
  ],
  "lastModified": "2026-06-16T22:39:24.700",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:alexander_v._lukyanov:lftp:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "47F5BBDA-3E9F-430B-8C79-C622ABBB14E3",
              "versionEndIncluding": "3.5.8"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "vendorComments": [
    {
      "comment": "This issue does not affect lftp as supplied with Red Hat Enterprise Linux 3.\n\nThis issue was addressed for Red Hat Enterprise Linux 5 by\nhttps://rhn.redhat.com/errata/RHSA-2009-1278.html\n\nThe Red Hat Security Response Team has rated this issue as having low security impact, a future update to Red Hat Enterprise Linux 4 may address this flaw.",
      "lastModified": "2009-09-02T00:00:00",
      "organization": "Red Hat"
    }
  ],
  "sourceIdentifier": "secalert@redhat.com"
}