CVE Vulnerabilities

CVE-2024-48651

Published: Nov 29, 2024 | Modified: Nov 29, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

In ProFTPD through 1.3.8b before cec01cc, supplemental group inheritance grants unintended access to GID 0 because of the lack of supplemental groups from mod_sql.

Affected Software

Name Vendor Start Version End Version
Proftpd-dfsg Ubuntu devel *
Proftpd-dfsg Ubuntu esm-apps/jammy *
Proftpd-dfsg Ubuntu esm-apps/noble *
Proftpd-dfsg Ubuntu jammy *
Proftpd-dfsg Ubuntu noble *
Proftpd-dfsg Ubuntu oracular *
Proftpd-dfsg Ubuntu upstream *

References