SafeTP Passive Mode Internal IP Address Revealing Vulnerability

SafeTP is a freely available, open source secure ftp client-server software package. It is available for Unix, Linux, and Microsoft Operating Systems.

It has been reported that under some circumstances, the SafeTP server may reveal sensitive network information. When a passive session is initiated in a specific manner, SafeTP may return the address of a system serving files that is behind at NAT firewall.


 

Privacy Statement
Copyright 2010, SecurityFocus