CVE-2014-8517

NameCVE-2014-8517
DescriptionThe fetch_url function in usr.bin/ftp/fetch.c in tnftp, as used in NetBSD 5.1 through 5.1.4, 5.2 through 5.2.2, 6.0 through 6.0.6, and 6.1 through 6.1.5 allows remote attackers to execute arbitrary commands via a | (pipe) character at the end of an HTTP redirect.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs767171

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
tnftp (PTS)buster20130505-3fixed
bullseye20200705-2fixed
bookworm20210827-4fixed
sid, trixie20230507-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
tnftpsource(unstable)20130505-2low767171

Notes

[wheezy] - tnftp <no-dsa> (Minor issue)
[squeeze] - tnftp <no-dsa> (Minor issue)
https://www.openwall.com/lists/oss-security/2014/10/28/4

Search for package or bug name: Reporting problems