CyberSec.Space Logo
返回 CVE 浏览器

CVE-2006-7094

HIGH
8.5
CVSS Severity Score
EPSS Score0.1030%
EPSS Percentile40.94th
Published2007年3月2日
Last Modified2026年4月23日

Vulnerability Description

ftpd, as used by Gentoo and Debian Linux, sets the gid to the effective uid instead of the effective group id before executing /bin/ls, which allows remote authenticated users to list arbitrary directories with the privileges of gid 0 and possibly enable additional attack vectors.

Affected Platforms (CPE)

📦
Ftpd

Ftpd

All versions

References & Advisories

相关漏洞威胁