8.5
CVE-2006-7094
- EPSS 2.56%
- Veröffentlicht 02.03.2007 21:18:00
- Zuletzt bearbeitet 16.06.2026 22:34:22
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
ftpd, as used by Gentoo and Debian Linux, sets the gid to the effective uid instead of the effective group id before executing /bin/ls, which allows remote authenticated users to list arbitrary directories with the privileges of gid 0 and possibly enable additional attack vectors.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.56% | 0.83 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 8.5 | 6.8 | 10 |
AV:N/AC:M/Au:S/C:C/I:C/A:C
|
http://bugs.debian.org/384454
http://bugs.gentoo.org/show_bug.cgi?id=155317
http://osvdb.org/34242
http://packages.qa.debian.org/l/linux-ftpd/news/20061125T181702Z.html
http://securityreason.com/securityalert/2330
http://www.securityfocus.com/archive/1/460742/100/0/threaded