HIGH · 8.5

CVE-2006-7094

ftpd, as used by Gentoo and Debian Linux, sets the gid to the effective uid instead of the effective group id before executing /bin/ls, which allows remote authenticated users to list arbitrary direct...

Vulnerability Description

ftpd, as used by Gentoo and Debian Linux, sets the gid to the effective uid instead of the effective group id before executing /bin/ls, which allows remote authenticated users to list arbitrary directories with the privileges of gid 0 and possibly enable additional attack vectors.

CVSS Score

8.5

HIGH

AV:N/AC:M/Au:S/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
GentooLinuxAll versions
FtpdFtpdAll versions
DebianDebian Linux4.0

References

FAQ

What is CVE-2006-7094?

CVE-2006-7094 is a vulnerability with a CVSS score of 8.5 (HIGH). ftpd, as used by Gentoo and Debian Linux, sets the gid to the effective uid instead of the effective group id before executing /bin/ls, which allows remote authenticated users to list arbitrary direct...

How severe is CVE-2006-7094?

CVE-2006-7094 has been rated HIGH with a CVSS base score of 8.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2006-7094?

Check the references section above for vendor advisories and patch information. Affected products include: Gentoo Linux, Ftpd Ftpd, Debian Debian Linux.