ProFTPD before 1.3.5rc1, when using the UserOwner directive, allows local users to modify the ownership of arbitrary files via a race condition and a symlink attack on the (1) MKD or (2) XMKD commands.
CVSS Details
- CVSS 3.1 Base Score: 2.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade proftpd-dfsg | Jul 30, 2024 | Jan 24, 2013 |
| Gentoo Linux | — | Upgrade net-ftp/proftpd. | Oct 30, 2017 | Jan 24, 2013 |
| Oracle Solaris | — | Upgrade service/network/ftp to version 1.3.4.0.3-0.175.1.11.0.3.0 on Solaris 11.1 | May 29, 2017 | Jan 24, 2013 |
| Proftp Proftpd | — | Update ProFTP ProFTPd to the latest version | Nov 6, 2025 | Jan 24, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub