lftp 3.7.15-1ubuntu2.1 source package in Ubuntu

Changelog

lftp (3.7.15-1ubuntu2.1) karmic-security; urgency=low

  * SECURITY UPDATE: arbitrary file overwrite via dot file download
    - debian/patches/CVE-2010-2251.dpatch: don't use server-provided names
      in src/{FileAccess,FileCopy,GetJob,commands,resource}.cc.
    - This update changes previous behaviour by ignoring the filename
      supplied by the server in the Content-Disposition header. To
      re-enable previous behaviour, use the new xfer:auto-rename setting.
    - CVE-2010-2251
 -- Marc Deslauriers <email address hidden>   Thu, 02 Sep 2010 15:34:40 -0400

Upload details

Uploaded by:
Marc Deslauriers
Uploaded to:
Karmic
Original maintainer:
Ubuntu Developers
Architectures:
any
Section:
net
Urgency:
Low Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Downloads

File Size SHA-256 Checksum
lftp_3.7.15.orig.tar.gz 2.0 MiB b951f39999663f6199bc2bdf3dc1f903907082844fb7c8229b9e4322f166cc67
lftp_3.7.15-1ubuntu2.1.diff.gz 14.9 KiB dec0596caeb4934e2ab533455054c157e24858c3692eb966bfd1d89ba369e04b
lftp_3.7.15-1ubuntu2.1.dsc 1.2 KiB 5a8ad5597c24b4cff8626861035914f0a737cb383e3fa7fb38d1acd96b025611

View changes file

Binary packages built by this source

lftp: No summary available for lftp in ubuntu karmic.

No description available for lftp in ubuntu karmic.