PT-2006-1027 · Debian+1 · Debian+1
Paul Szabo
·
Published
2006-11-07
·
Updated
2008-09-05
·
CVE-2006-5778
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
linux-ftpd version 0.17
possibly other versions of linux-ftpd
Description:
The issue allows local users to bypass intended access restrictions. A local attacker can exploit this to redirect their home directory to a restricted directory, potentially leading to unauthorized access. Multiple vulnerabilities in the ftpd package of the Debian GNU/Linux operating system can be exploited by a local attacker, which may compromise the confidentiality, integrity, and availability of protected information.
Recommendations:
For linux-ftpd version 0.17, consider updating to a newer version that addresses this issue, if available.
For possibly other versions of linux-ftpd, update to a version that includes the necessary security fixes.
As a temporary workaround, consider restricting access to sensitive directories to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Debian
Linux-Ftpd