Vulnerability identifier: #VU46743
Vulnerability risk: Medium
Exploitation vector: Network
Exploit availability: No
Vendor: FreeBSD Foundation
The vulnerability allows a remote user to escalate privileges on the system.
The vulnerability exists due to an error in ftpd(8) sandbox implementation, combined with capabilities available to authenticated FTP users. A remote FTP user can bypass restrictions, configured with ftpchroot(5) and gain privileged access to the system.
Note, this vulnerability cannot be exploited by users with anonymous access to FTP server.
Install updates from vendor's website.
Vulnerable software versions
FreeBSD: 11.0, 11.1, 11.2, 11.3, 11.4, 12.0, 12.1, 12.2
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.