lftp 3.6.1-1ubuntu0.1 source package in Ubuntu

Changelog

lftp (3.6.1-1ubuntu0.1) hardy-security; urgency=low

  * SECURITY UPDATE: arbitrary file overwrite via dot file download
    - debian/patches/CVE-2010-2251.dpatch: don't use server-provided names
      in src/{FileAccess,FileCopy,GetJob,commands,resource}.cc.
    - This update changes previous behaviour by ignoring the filename
      supplied by the server in the Content-Disposition header. To
      re-enable previous behaviour, use the new xfer:auto-rename setting.
    - CVE-2010-2251
 -- Marc Deslauriers <email address hidden>   Thu, 02 Sep 2010 15:57:12 -0400

Upload details

Uploaded by:
Marc Deslauriers
Uploaded to:
Hardy
Original maintainer:
Ubuntu Developers
Architectures:
any
Section:
net
Urgency:
Low Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Downloads

File Size SHA-256 Checksum
lftp_3.6.1.orig.tar.gz 1.7 MiB 3617ebff4564aac5837cff4cd51042e6863d6017226441356d2eabf5a8e2aae7
lftp_3.6.1-1ubuntu0.1.diff.gz 13.1 KiB 48a648bcc3081f87ab870d7e7d12fabd820e1a6f903f8977071b7a481c3a79ac
lftp_3.6.1-1ubuntu0.1.dsc 735 bytes f07abc39eb7ebcfc5e607d39a6f33552869a12a57a719948a9f2e8c3e1cc081c

View changes file

Binary packages built by this source

lftp: No summary available for lftp in ubuntu hardy.

No description available for lftp in ubuntu hardy.