CVE Vulnerabilities

CVE-2011-0988

Published: Apr 18, 2011 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.4 MEDIUM
AV:L/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

pure-ftpd 1.0.22, as used in SUSE Linux Enterprise Server 10 SP3 and SP4, and Enterprise Desktop 10 SP3 and SP4, when running OES Netware extensions, creates a world-writeable directory, which allows local users to overwrite arbitrary files and gain privileges via unspecified vectors.

Affected Software

NameVendorStart VersionEnd Version
Pure-ftpdPureftpd1.0.22 (including)1.0.22 (including)
Suse_linuxNovell10-sp3 (including)10-sp3 (including)
Suse_linuxNovell10-sp4 (including)10-sp4 (including)
Suse_linuxNovell11-sp3 (including)11-sp3 (including)
Suse_linuxNovell11-sp4 (including)11-sp4 (including)

References