Описание
In ProFTPD through 1.3.8b before cec01cc, supplemental group inheritance grants unintended access to GID 0 because of the lack of supplemental groups from mod_sql.
Пакеты
Пакет | Статус | Версия исправления | Релиз | Тип |
---|---|---|---|---|
proftpd-dfsg | fixed | 1.3.8.b+dfsg-4 | package |
Примечания
https://github.com/proftpd/proftpd/issues/1830
Fixed by: https://github.com/proftpd/proftpd/commit/cec01cc0a2523453e5da5a486bc6d977c3768db1 (master)
Fixed by: https://github.com/proftpd/proftpd/commit/5031d498a71c493b9659e2b5ccafde58b0897e30 (1.3.8 branch)
EPSS
Связанные уязвимости
In ProFTPD through 1.3.8b before cec01cc, supplemental group inheritance grants unintended access to GID 0 because of the lack of supplemental groups from mod_sql.
In ProFTPD through 1.3.8b before cec01cc, supplemental group inheritance grants unintended access to GID 0 because of the lack of supplemental groups from mod_sql.
In ProFTPD through 1.3.8b before cec01cc, supplemental group inheritance grants unintended access to GID 0 because of the lack of supplemental groups from mod_sql.
Уязвимость компонента mod_sql FTP-сервера ProFTPD, позволяющая нарушителю повысить свои привилегии
EPSS