PT-2017-17724 · Proftpd+2 · Proftpd+2

CVE-2017-7418

·

Publicado

2017-04-04

·

Atualizado

2024-10-14

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions ProFTPD versions prior to 1.3.5e ProFTPD versions 1.3.6 prior to 1.3.6rc5
Description The issue allows attackers with local access to bypass the AllowChrootSymlinks control by replacing a path component (other than the last one) with a symbolic link. This could be exploited by an attacker who is not granted full filesystem access but can reconfigure the home directory of an FTP user.
Recommendations For ProFTPD versions prior to 1.3.5e, update to version 1.3.5e or later. For ProFTPD versions 1.3.6 prior to 1.3.6rc5, update to version 1.3.6rc5 or later.

Exploit

Correção

Link Following

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2018-1000
ALT-PU-2021-2692
ALT-PU-2023-5874
ALT-PU-2024-13729
CVE-2017-7418
MGASA-2017-0115
OPENSUSE-SU-2019:1836-1
OPENSUSE-SU-2019:1870-1
OPENSUSE-SU-2019_1836-1
OPENSUSE-SU-2020:0031-1
OPENSUSE-SU-2020_0031-1
OPENSUSE-SU-2024:11196-1

Produtos afetados

Alt Linux
Proftpd
Suse