FreeBSD : FreeBSD -- Remote command execution in ftp(1) (7488378d-6007-11e6-a6c3-14dae9d210b8)
High Nessus Plugin ID 92913
SynopsisThe remote FreeBSD host is missing one or more security-related updates.
DescriptionA malicious HTTP server could cause ftp(1) to execute arbitrary commands. Impact : When operating on HTTP URIs, the ftp(1) client follows HTTP redirects, and uses the part of the path after the last '/' from the last resource it accesses as the output filename if '-o' is not specified.
If the output file name provided by the server begins with a pipe ('|'), the output is passed to popen(3), which might be used to execute arbitrary commands on the ftp(1) client machine.
SolutionUpdate the affected packages.