File _patchinfo of Package patchinfo.10482
<patchinfo incident="10482">
<issue tracker="bnc" id="1120946">lftp: when using sftp not all password prompts are recognized</issue>
<issue tracker="bnc" id="1103367">VUL-0: CVE-2018-10916: lftp: particular remote file names may lead to current working directory erased</issue>
<issue tracker="cve" id="2018-10916"/>
<category>security</category>
<rating>moderate</rating>
<packager>psimons</packager>
<description>This update for lftp fixes the following issues:
Security issue fixed:
- CVE-2018-10916: Fixed an improper file name sanitization which could lead to loss of integrity of
the local system (bsc#1103367).
Other issue addressed:
- The SSH login handling code detects password prompts more reliably (bsc#1120946).
</description>
<summary>Security update for lftp</summary>
</patchinfo>