vulnerability

FreeBSD: VID-6d334fdb-f7e7-11ea-88f8-901b0ef719ab (CVE-2020-7468): FreeBSD -- ftpd privilege escalation via ftpchroot feature

Severity
9
CVSS
(AV:N/AC:L/Au:S/C:C/I:C/A:C)
Published
Sep 16, 2020
Added
Sep 17, 2020
Modified
Dec 10, 2025

Description

Problem Description: A ftpd(8) bug in the implementation of the file system sandbox, combined with capabilities available to an authenticated FTP user, can be used to escape the file system restriction configured in ftpchroot(5). Moreover, the bug allows a malicious client to gain root privileges. Impact: A malicious FTP user can gain privileged access to an affected system.

Solutions

freebsd-upgrade-base-12_1-release-p10freebsd-upgrade-base-11_4-release-p4freebsd-upgrade-base-11_3-release-p14
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.