PT-2000-1403 · Netbsd · Netbsd

Publicado

2000-05-28

·

Atualizado

2008-09-10

·

CVE-2000-0462

CVSS v2.0

2.1

Baixa

VetorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions NetBSD version 1.4.2
Description The issue concerns the ftpd in NetBSD, which fails to properly parse entries in /etc/ftpchroot. As a result, it does not chroot the specified users, allowing them to access files outside of their home directory.
Recommendations For NetBSD version 1.4.2, consider updating the /etc/ftpchroot configuration to properly restrict user access until a patch is available. As a temporary workaround, restrict access to sensitive files and directories to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2000-0462

Produtos afetados

Netbsd