FreeBSD : tnftp -- mget does not check for directory escapes (f92e1bbc-5e18-11d9-839a-0050da134090)
Medium Nessus Plugin ID 19181
The remote FreeBSD host is missing a security-related update.
When downloading a batch of files from an FTP server the mget command does not check for directory escapes. A specially crafted file on the FTP server could then potentially overwrite an existing file of the user.