8.5

CVE-2006-7094

ftpd, as used by Gentoo and Debian Linux, sets the gid to the effective uid instead of the effective group id before executing /bin/ls, which allows remote authenticated users to list arbitrary directories with the privileges of gid 0 and possibly enable additional attack vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
FtpdFtpd
   GentooLinux
FtpdFtpd
   DebianDebian Linux Version4.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.56% 0.83
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.5 6.8 10
AV:N/AC:M/Au:S/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://bugs.debian.org/384454
http://bugs.gentoo.org/show_bug.cgi?id=155317
Patch
http://osvdb.org/34242
http://packages.qa.debian.org/l/linux-ftpd/news/20061125T181702Z.html
http://securityreason.com/securityalert/2330
http://www.securityfocus.com/archive/1/460742/100/0/threaded