Информационная безопасность
[RU] switch to
English Version



CVECVE-2006-5778
СтатусCandidate
Описаниеftpd in linux-ftpd 0.17, and possibly other versions, performs a chdir before setting the UID, which allows local users to bypass intended access restrictions by redirecting their home directory to a restricted directory.
ВажностьMedium
CVSS score4,9
CVSS vector(AV:L/AC:L/Au:NR/C:P/I:P/A:P/B:N)
PhaseAssigned (07.11.2006)
NVD:http://nvd.nist.gov/nvd.cfm?cvename=CVE-2006-5778
ReferencesBID : 21000
 CONFIRM : http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=3...
 DEBIAN : DSA-1217
 FULLDISC : 20060825 ftpd chdir() while root
 GENTOO : GLSA-200611-05
 SECUNIA : 22997
SecurityVulns:Обход защиты в Netkit FTP Server (protection bypass)

О сайте | Условия использования
© SecurityVulns, 3APA3A, Владимир Дубровин
Нижний Новгород

 
 



Rating@Mail.ru
test server