PT-2006-1027 · Debian+1 · Debian+1
Paul Szabo
·
Publicado
2006-11-07
·
Atualizado
2008-09-05
·
CVE-2006-5778
CVSS v2.0
4.6
Média
| Vetor | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
linux-ftpd version 0.17
possibly other versions of linux-ftpd
Description:
The issue allows local users to bypass intended access restrictions. A local attacker can exploit this to redirect their home directory to a restricted directory, potentially leading to unauthorized access. Multiple vulnerabilities in the ftpd package of the Debian GNU/Linux operating system can be exploited by a local attacker, which may compromise the confidentiality, integrity, and availability of protected information.
Recommendations:
For linux-ftpd version 0.17, consider updating to a newer version that addresses this issue, if available.
For possibly other versions of linux-ftpd, update to a version that includes the necessary security fixes.
As a temporary workaround, consider restricting access to sensitive directories to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Debian
Linux-Ftpd