1.2

CVE-2012-6095

ProFTPD before 1.3.5rc1, when using the UserOwner directive, allows local users to modify the ownership of arbitrary files via a race condition and a symlink attack on the (1) MKD or (2) XMKD commands.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Proftpd ≫ Proftpd Version <= 1.3.4
Proftpd ≫ Proftpd Version 1.2.0
Proftpd ≫ Proftpd Version 1.2.0 Update pre10
Proftpd ≫ Proftpd Version 1.2.0 Update pre9
Proftpd ≫ Proftpd Version 1.2.0 Update rc1
Proftpd ≫ Proftpd Version 1.2.0 Update rc2
Proftpd ≫ Proftpd Version 1.2.0 Update rc3
Proftpd ≫ Proftpd Version 1.2.1
Proftpd ≫ Proftpd Version 1.2.2
Proftpd ≫ Proftpd Version 1.2.2 Update rc1
Proftpd ≫ Proftpd Version 1.2.2 Update rc2
Proftpd ≫ Proftpd Version 1.2.2 Update rc3
Proftpd ≫ Proftpd Version 1.2.3
Proftpd ≫ Proftpd Version 1.2.4
Proftpd ≫ Proftpd Version 1.2.5
Proftpd ≫ Proftpd Version 1.2.5 Update rc1
Proftpd ≫ Proftpd Version 1.2.5 Update rc2
Proftpd ≫ Proftpd Version 1.2.5 Update rc3
Proftpd ≫ Proftpd Version 1.2.6
Proftpd ≫ Proftpd Version 1.2.6 Update rc1
Proftpd ≫ Proftpd Version 1.2.6 Update rc2
Proftpd ≫ Proftpd Version 1.2.7
Proftpd ≫ Proftpd Version 1.2.7 Update rc1
Proftpd ≫ Proftpd Version 1.2.7 Update rc2
Proftpd ≫ Proftpd Version 1.2.7 Update rc3
Proftpd ≫ Proftpd Version 1.2.8
Proftpd ≫ Proftpd Version 1.2.8 Update rc1
Proftpd ≫ Proftpd Version 1.2.8 Update rc2
Proftpd ≫ Proftpd Version 1.2.9
Proftpd ≫ Proftpd Version 1.2.9 Update rc1
Proftpd ≫ Proftpd Version 1.2.9 Update rc2
Proftpd ≫ Proftpd Version 1.2.9 Update rc3
Proftpd ≫ Proftpd Version 1.2.10
Proftpd ≫ Proftpd Version 1.2.10 Update rc1
Proftpd ≫ Proftpd Version 1.2.10 Update rc2
Proftpd ≫ Proftpd Version 1.2.10 Update rc3
Proftpd ≫ Proftpd Version 1.3.0
Proftpd ≫ Proftpd Version 1.3.0 Update a
Proftpd ≫ Proftpd Version 1.3.0 Update rc1
Proftpd ≫ Proftpd Version 1.3.0 Update rc2
Proftpd ≫ Proftpd Version 1.3.0 Update rc3
Proftpd ≫ Proftpd Version 1.3.0 Update rc4
Proftpd ≫ Proftpd Version 1.3.0 Update rc5
Proftpd ≫ Proftpd Version 1.3.1
Proftpd ≫ Proftpd Version 1.3.1 Update rc1
Proftpd ≫ Proftpd Version 1.3.1 Update rc2
Proftpd ≫ Proftpd Version 1.3.1 Update rc3
Proftpd ≫ Proftpd Version 1.3.2
Proftpd ≫ Proftpd Version 1.3.2 Update a
Proftpd ≫ Proftpd Version 1.3.2 Update b
Proftpd ≫ Proftpd Version 1.3.2 Update c
Proftpd ≫ Proftpd Version 1.3.2 Update d
Proftpd ≫ Proftpd Version 1.3.2 Update e
Proftpd ≫ Proftpd Version 1.3.2 Update rc1
Proftpd ≫ Proftpd Version 1.3.2 Update rc2
Proftpd ≫ Proftpd Version 1.3.2 Update rc3
Proftpd ≫ Proftpd Version 1.3.2 Update rc4
Proftpd ≫ Proftpd Version 1.3.3
Proftpd ≫ Proftpd Version 1.3.3 Update a
Proftpd ≫ Proftpd Version 1.3.3 Update b
Proftpd ≫ Proftpd Version 1.3.3 Update c
Proftpd ≫ Proftpd Version 1.3.3 Update rc1
Proftpd ≫ Proftpd Version 1.3.3 Update rc2
Proftpd ≫ Proftpd Version 1.3.3 Update rc3
Proftpd ≫ Proftpd Version 1.3.3 Update rc4
Proftpd ≫ Proftpd Version 1.3.4 Update rc1
Proftpd ≫ Proftpd Version 1.3.4 Update rc2
Proftpd ≫ Proftpd Version 1.3.4 Update rc3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.69% 0.48
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 1.2 1.9 2.9
AV:L/AC:H/Au:N/C:N/I:P/A:N
CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

http://bugs.proftpd.org/show_bug.cgi?id=3841
http://proftpd.org/docs/NEWS-1.3.5rc1
http://secunia.com/advisories/51823
Vendor Advisory
http://www.debian.org/security/2013/dsa-2606
http://www.openwall.com/lists/oss-security/2013/01/07/3