CVE-2019-5429: Debian Linux
High severity, CVSS 7.8. EPSS: 2.8% chance of exploitation in the next 30 days.
Untrusted search path in FileZilla before 3.41.0-rc1 allows an attacker to gain privileges via a malicious 'fzsftp' binary in the user's home directory.
Affected products
- Debian Debian Linux: version 9.0 only
- Fedoraproject Fedora: version 28 only
- Filezilla-Project Filezilla Client: before 3.41.0 (fixed in 3.41.0)
Published 2019-04-29. Last modified 2026-06-17.