Computer Security
[EN] securityvulns.ru
no-pyccku



CVECVE-2006-5778
StatusCandidate
Descriptionftpd in linux-ftpd 0.17, and possibly other versions, performs a chdir before setting the UID, which allows local users to bypass intended access restrictions by redirecting their home directory to a restricted directory.
SeverityMedium
CVSS score4,9
CVSS vector(AV:L/AC:L/Au:NR/C:P/I:P/A:P/B:N)
PhaseAssigned (07.11.2006)
NVD:http://nvd.nist.gov/nvd.cfm?cvename=CVE-2006-5778
ReferencesBID : 21000
 CONFIRM : http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=3...
 DEBIAN : DSA-1217
 FULLDISC : 20060825 ftpd chdir() while root
 GENTOO : GLSA-200611-05
 SECUNIA : 22997
SecurityVulns:Netkit FTP Server protection bypass

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server