CVE-2009-5012

Source
https://cve.org/CVERecord?id=CVE-2009-5012
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2009-5012.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2009-5012
Aliases
Downstream
Withdrawn
2026-01-27T04:10:06.478800Z
Published
2010-10-19T20:00:03Z
Modified
2026-01-27T04:10:06.478800Z
Summary
[none]
Details

ftpserver.py in pyftpdlib before 0.5.2 does not require the l permission for the MLST command, which allows remote authenticated users to bypass intended access restrictions and list the root directory via an FTP session.

References

Affected packages