Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Debian: DSA-5827-1 proftpd Security Advisory on Group Access Issue

debian
Calendar Grey December 10, 2024
Debian Logo
Debian Security Notice DSA-5827-1 concerning proftpd unintended access vulnerability and suggested mitigations.
Brian Ristuccia discovered that in ProFTPD, a powerful modular FTP/SFTP/FTPS server, supplemental group inheritance grants unintended access to GID 0 because of the lack of supplem...

Summary

For the stable distribution (bookworm), this problem has been fixed in
version 1.3.8+dfsg-4+deb12u4.

We recommend that you upgrade your proftpd-dfsg packages.

For the detailed security status of proftpd-dfsg please refer to its
security tracker page at:
https://security-tracker.debian.org/tracker/source-package/proftpd-dfsg

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Severity
critical
Lowest
Low
Medium
High
Critical

Package: proftpd-dfsg
CVE ID: CVE-2024-48651

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here