Vulnerability identifier: #VU43153
Vulnerability risk: Low
CVSSv4.0: 0.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID:
CWE-ID:
CWE-362
Exploitation vector: Network
Exploit availability: No
Vulnerable software:
ProFTPD
Server applications /
File servers (FTP/HTTP)
Vendor: ProFTPD
Description
The vulnerability allows a remote non-authenticated attacker to manipulate data.
ProFTPD before 1.3.5rc1, when using the UserOwner directive, allows local users to modify the ownership of arbitrary files via a race condition and a symlink attack on the (1) MKD or (2) XMKD commands.
Mitigation
Install update from vendor's website.
Vulnerable software versions
ProFTPD: 1.2.0 - 1.3.4
External links
https://bugs.proftpd.org/show_bug.cgi?id=3841
https://proftpd.org/docs/NEWS-1.3.5rc1
https://secunia.com/advisories/51823
https://www.debian.org/security/2013/dsa-2606
https://www.openwall.com/lists/oss-security/2013/01/07/3
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.