Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

Mageia 9 MGASA-2025-0015 critical: proftpd unintended access issue

mageia
Calendar Grey January 20, 2025
Dist Mageia Esm H88
Mageia has released security announcement MGASA-2025-0015 concerning proftpd which mitigates inadvertent GID access vulnerabilities through recent updates.
In ProFTPD through 1.3.8b before cec01cc, supplemental group inheritance grants unintended access to GID 0 because of the lack of supplemental groups from mod_sql

Summary

In ProFTPD through 1.3.8b before cec01cc, supplemental group inheritance grants unintended access to GID 0 because of the lack of supplemental groups from mod_sql. (CVE-2024-48651)

References

- https://bugs.mageia.org/show_bug.cgi?id=33922

-

- https://www.cve.org/CVERecord?id=CVE-2024-48651

Resolution

SRPMS

- 9/core/proftpd-1.3.8c-1.mga9

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 20 Jan 2025
URL: https://advisories.mageia.org/MGASA-2025-0015.html
Type: security
CVE: CVE-2024-48651

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here