CVE Database
/

CVE-2014-1693

Back to search

CVE-2014-1693

Published: Dec 8, 2014

Modified: Aug 6, 2024

PUBLISHED

Description

Multiple CRLF injection vulnerabilities in the FTP module in Erlang/OTP R15B03 allow context-dependent attackers to inject arbitrary FTP commands via CRLF sequences in the (1) user, (2) account, (3) cd, (4) ls, (5) nlist, (6) rename, (7) delete, (8) mkdir, (9) rmdir, (10) recv, (11) recv_bin, (12) recv_chunk_start, (13) send, (14) send_bin, (15) send_chunk_start, (16) append_chunk_start, (17) append, or (18) append_bin command.

VendorProductVersions

n/a

n/a

affected
n/a

References

USN-3571-1
vendor-advisory
x_refsource_UBUNTU
FEDORA-2014-15394
vendor-advisory
x_refsource_FEDORA
MDVSA-2015:174
vendor-advisory
x_refsource_MANDRIVA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now