This has been known for a long time: http://www.security-express.com/archives/bugtraq/1999-q4/0405.html
There is an easy solution to this which don't cut functionality: in ftpconversions place " -- " before "%s" in every line which has tar (probably on all lines is a good idea). " -- " terminates the arguments passed to tar, so programs can't be injected.
linux distributions were notified about the solution, debian released an advisory at: http://www.debian.org/security/2003/dsa-377
georgi
_________________________________________________________________
Add photos to your messages with MSN 8. Get 2 months FREE*. http://join.msn.com/?page=features/featuredemail
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html
