#VU46743 Security restrictions bypass

Published: 2020-09-16

Vulnerability identifier: #VU46743

Vulnerability risk: Medium

CVSSv3: 7.1 [CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N/E:U/RL:O/RC:C]

CVE-ID: CVE-2020-7468


Exploitation vector: Network

Exploit availability: No

Vulnerable software: FreeBSD
Operating systems & Components / Operating system

Vendor: FreeBSD Foundation


The vulnerability allows a remote user to escalate privileges on the system.

The vulnerability exists due to an error in ftpd(8) sandbox implementation, combined with capabilities available to authenticated FTP users. A remote FTP user can bypass restrictions, configured with ftpchroot(5) and gain privileged access to the system.

Note, this vulnerability cannot be exploited by users with anonymous access to FTP server.

Install updates from vendor's website.

Vulnerable software versions

FreeBSD: 11.0, 11.1, 11.2, 11.3, 11.4, 12.0, 12.1, 12.2


External links

Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

Latest bulletins with this vulnerability