4.6
CVSSv2

CVE-2006-5778

Published: 07/11/2006 Updated: 05/09/2008
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

ftpd in linux-ftpd 0.17, and possibly other versions, performs a chdir before setting the UID, which allows local users to bypass intended access restrictions by redirecting their home directory to a restricted directory.

Vulnerable Product Search on Vulmon Subscribe to Product

linux-ftpd-ssl linux-ftpd-ssl 0.17

Vendor Advisories

Debian Bug report logs - #384454 ftpd: Does not handle symlink? NFS? home directory Package: ftpd; Maintainer for ftpd is Mats Erik Andersson <matsandersson@gisladiskerse>; Source for ftpd is src:linux-ftpd (PTS, buildd, popcon) Reported by: Paul Szabo <psz@mathsusydeduau> Date: Thu, 24 Aug 2006 11:34:22 UTC Se ...