Gentoo Archives: gentoo-announce

From: Sam James <sam@g.o>
To: gentoo-announce@l.g.o
Subject: [gentoo-announce] [ GLSA 202007-51 ] FileZilla: Untrusted search path
Date: Mon, 27 Jul 2020 01:38:53
Message-Id: B6FD3538-DA18-4658-B601-B17A94D580EC@gentoo.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 202007-51
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 https://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: FileZilla: Untrusted search path
9 Date: July 27, 2020
10 Bugs: #717726
11 ID: 202007-51
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 A vulnerability was found in FileZilla which might allow privilege
19 escalation.
20
21 Background
22 ==========
23
24 FileZilla is an open source FTP client.
25
26 Affected packages
27 =================
28
29 -------------------------------------------------------------------
30 Package / Vulnerable / Unaffected
31 -------------------------------------------------------------------
32 1 net-ftp/filezilla < 3.47.2.1 >= 3.47.2.1
33
34 Description
35 ===========
36
37 It was discovered that FileZilla uses an untrusted search path.
38
39 Impact
40 ======
41
42 An attacker could use a malicious binary to escalate privileges.
43
44 Workaround
45 ==========
46
47 There is no known workaround at this time.
48
49 Resolution
50 ==========
51
52 All FileZilla users should upgrade to the latest version:
53
54 # emerge --sync
55 # emerge --ask --oneshot --verbose ">=net-ftp/filezilla-3.47.2.1"
56
57 References
58 ==========
59
60 [ 1 ] CVE-2019-5429
61 https://nvd.nist.gov/vuln/detail/CVE-2019-5429
62
63 Availability
64 ============
65
66 This GLSA and any updates to it are available for viewing at
67 the Gentoo Security Website:
68
69 https://security.gentoo.org/glsa/202007-51
70
71 Concerns?
72 =========
73
74 Security is a primary focus of Gentoo Linux and ensuring the
75 confidentiality and security of our users' machines is of utmost
76 importance to us. Any security concerns should be addressed to
77 security@g.o or alternatively, you may file a bug at
78 https://bugs.gentoo.org.
79
80 License
81 =======
82
83 Copyright 2020 Gentoo Foundation, Inc; referenced text
84 belongs to its owner(s).
85
86 The contents of this document are licensed under the
87 Creative Commons - Attribution / Share Alike license.
88
89 https://creativecommons.org/licenses/by-sa/2.5

Attachments

File name MIME type
signature.asc application/pgp-signature