In ProFTPD through 1.3.8b before cec01cc, supplemental group inheritance
grants unintended access to GID 0 because of the lack of supplemental
groups from mod_sql. (CVE-2024-48651)
- https://bugs.mageia.org/show_bug.cgi?id=33922
-
- https://www.cve.org/CVERecord?id=CVE-2024-48651
- 9/core/proftpd-1.3.8c-1.mga9
Get the latest Linux and open source security news straight to your inbox.