CVE-2014-1693
Publication date 8 December 2014
Last updated 24 July 2024
Ubuntu priority
Multiple CRLF injection vulnerabilities in the FTP module in Erlang/OTP R15B03 allow context-dependent attackers to inject arbitrary FTP commands via CRLF sequences in the (1) user, (2) account, (3) cd, (4) ls, (5) nlist, (6) rename, (7) delete, (8) mkdir, (9) rmdir, (10) recv, (11) recv_bin, (12) recv_chunk_start, (13) send, (14) send_bin, (15) send_chunk_start, (16) append_chunk_start, (17) append, or (18) append_bin command.
Status
Package | Ubuntu Release | Status |
---|---|---|
erlang | ||
16.04 LTS xenial |
Not affected
|
|
14.04 LTS trusty |
Fixed 1:16.b.3-dfsg-1ubuntu2.2
|
|
Notes
jdstrand
requires MITM between erlang system and ftp server or for the web server to not do input sanitization
References
Related Ubuntu Security Notices (USN)
- USN-3571-1
- Erlang vulnerabilities
- 14 February 2018