CVE Vulnerabilities

CVE-2006-7094

Published: Mar 02, 2007 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
8.5 HIGH
AV:N/AC:M/Au:S/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

ftpd, as used by Gentoo and Debian Linux, sets the gid to the effective uid instead of the effective group id before executing /bin/ls, which allows remote authenticated users to list arbitrary directories with the privileges of gid 0 and possibly enable additional attack vectors.

Affected Software

NameVendorStart VersionEnd Version
LinuxGentoo**
Linux-ftpdUbuntudapper*
Linux-ftpdUbuntuedgy*
Linux-ftpdUbuntufeisty*

References