tnftp: Arbitrary code execution tnftp is vulnerable to remote code execution if output file is not specified. tnftp 2016-11-15 2016-11-15: 1 527302 remote 20141104 20141104

tnftp is a NetBSD FTP client with several advanced features.

The fetch_url function in usr.bin/ftp/fetch.c allows remote attackers to execute arbitrary commands via a

A remote attacker could possibly execute arbitrary code with the privileges of the process.

There is no known workaround at this time.

All tnftp users should upgrade to the latest version:

# emerge --sync # emerge --ask --verbose --oneshot ">=net-ftp/tnftp-20141104"
CVE-2014-8517 BlueKnight b-man