CVE-2006-7094
ftpd, as used by Gentoo and Debian Linux, sets the gid to the effective uid instead of the effective group id before executing /bin/ls, which allows remote authenticated users to list arbitrary directories with the privileges of gid 0 and possibly…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.56%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
ftpd, as used by Gentoo and Debian Linux, sets the gid to the effective uid instead of the effective group id before executing /bin/ls, which allows remote authenticated users to list arbitrary directories with the privileges of gid 0 and possibly enable additional attack vectors.
- CVSS 2.0
- 8.5 HIGHAV:N/AC:M/Au:S/C:C/I:C/A:C
- EPSS
- 2.56% probability · 84th percentile
- CISA KEV
- Not listed
- Affected
- ftpd/ftpd
- Source
- cve@mitre.org
References
- http://bugs.debian.org/384454
- http://bugs.gentoo.org/show_bug.cgi?id=155317Patch
- http://osvdb.org/34242
- http://packages.qa.debian.org/l/linux-ftpd/news/20061125T181702Z.html
- http://securityreason.com/securityalert/2330
- http://www.securityfocus.com/archive/1/460742/100/0/threaded
- http://bugs.debian.org/384454
- http://bugs.gentoo.org/show_bug.cgi?id=155317Patch
- http://osvdb.org/34242
- http://packages.qa.debian.org/l/linux-ftpd/news/20061125T181702Z.html
- http://securityreason.com/securityalert/2330
- http://www.securityfocus.com/archive/1/460742/100/0/threaded
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.