A vulnerability has been discovered in CrushFTP, which could allow for unauthorized access. CrushFTP is a proprietary multi-protocol, multi-platform file transfer server. The vulnerability is mitigated if the DMZ feature of CrushFTP is in place. Successful exploitation of this vulnerability could allow an attacker to remotely control the compromised server and execute remote code. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
More Stories
USN-7418-1: Ruby vulnerabilities
It was discovered that Ruby incorrectly handled parsing of an XML document that has specific XML characters in an attribute...
thunderbird-128.9.0-1.fc40
FEDORA-2025-4841d72caf Packages in this update: thunderbird-128.9.0-1.fc40 Update description: Update to 128.9.0 https://www.thunderbird.net/en-US/thunderbird/128.9.0esr/releasenotes/ https://www.mozilla.org/en-US/security/advisories/mfsa2025-24/ Read More
thunderbird-128.9.0-1.fc41
FEDORA-2025-9a271ccfb3 Packages in this update: thunderbird-128.9.0-1.fc41 Update description: Update to 128.9.0 https://www.thunderbird.net/en-US/thunderbird/128.9.0esr/releasenotes/ https://www.mozilla.org/en-US/security/advisories/mfsa2025-24/ Read More
php-tcpdf-6.9.1-1.fc40
FEDORA-2025-b5809de628 Packages in this update: php-tcpdf-6.9.1-1.fc40 Update description: Version 6.9.1 (2025-04-03) Fixed Path Traversal security vulnerability reported by Positive Technologies....
php-tcpdf-6.9.1-1.fc42
FEDORA-2025-39c7a4c7ce Packages in this update: php-tcpdf-6.9.1-1.fc42 Update description: Version 6.9.1 (2025-04-03) Fixed Path Traversal security vulnerability reported by Positive Technologies....
php-tcpdf-6.9.1-1.fc41
FEDORA-2025-85549e07c8 Packages in this update: php-tcpdf-6.9.1-1.fc41 Update description: Version 6.9.1 (2025-04-03) Fixed Path Traversal security vulnerability reported by Positive Technologies....