Achrimede's Gftpd Remote Privilege...

- AV AC AU C I A
发布: 2003-02-21
修订: 2025-04-13

A vulnerabilty has been discovered in Archimede's glftpd which may allow an unauthorized user to obtain root privileges. When adding a 'oneliner' string on the FTP server, root privileges are required to update the global FTP file 'oneliners'. It has been reported that glftpd fails to effectively drop privileges after updating the said file. Exploitation of this issue may allow an attacker to obtain an effective user identification of 'root'. It should be noted that the user would still be contained within the established FTP chroot environment.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息